• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
malicious npm packages exfiltrate hundreds of developer ssh keys via

Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub

You are here: Home / General Cyber Security News / Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub
January 23, 2024

Two destructive offers learned on the npm package deal registry have been found to leverage GitHub to retailer Base64-encrypted SSH keys stolen from developer techniques on which they ended up put in.

The modules named warbeast2000 and kodiak2k have been printed at the begin of the month, attracting 412 and 1,281 downloads right before they ended up taken down by the npm maintainers. The most latest downloads occurred on January 21, 2024.

Software package supply chain security agency ReversingLabs, which manufactured the discovery, reported there were eight distinct versions of warbeast2000 and extra than 30 variations of kodiak2k.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Both of those the modules are developed to operate a postinstall script after set up, which is intended to retrieve and execute two different JavaScript data files.

Cybersecurity

Although warbeast2000 attempts to obtain the personal SSH critical, kodiak2k is developed to glimpse for a vital named “meow,” increasing the possibility that the danger actor probable used a placeholder title during the early levels of the improvement.

“This second phase malicious script reads the personal SSH essential stored in the id_rsa file found in the /.ssh listing,” security researcher Lucija Valentić claimed. “It then uploaded the Foundation64-encoded key to an attacker-managed GitHub repository.”

Subsequent versions of kodiak2k were being found to execute a script discovered in an archived GitHub project hosting the Empire write-up-exploitation framework. The script is capable of launching the Mimikatz hacking device to dump credentials from procedure memory.

“The marketing campaign is just the most up-to-date example of cybercriminals and destructive actors applying open source package deal managers and linked infrastructure to help malicious software program supply chain campaigns that goal progress corporations and close-consumer companies,” Valentić said.

Uncovered this posting attention-grabbing? Follow us on Twitter  and LinkedIn to read through extra distinctive content we post.


Some components of this article are sourced from:
thehackernews.com

Previous Post: «"activator" alert: macos malware hides in cracked apps, targeting crypto “Activator” Alert: MacOS Malware Hides in Cracked Apps, Targeting Crypto Wallets
Next Post: VexTrio: The Uber of Cybercrime – Brokering Malware for 60+ Affiliates vextrio: the uber of cybercrime brokering malware for 60+»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.