Identification of Numerous Malicious Packages on NPM Engaging in Host and Network Data Collection

مقالات

Dozens of malicious packages on NPM collect host and network data

Script designed to delete Vue.js-related files on June 19–30, 2023
Script designed to delete Vue.js-related files on June 19–30, 2023
Source: Socket

The threat actor responsible for this campaign, operating under the pseudonym ‘xuxingfeng’, also published several legitimate packages to enhance the credibility of their account and evade detection.

While the immediate threat may have diminished due to the reliance on hardcoded dates, it remains imperative to uninstall these packages. The author could potentially issue updates that re-initiate destructive payloads in the future.