By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Thousands Download Malicious npm Libraries Impersonating Legitimate Tools
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Thousands Download Malicious npm Libraries Impersonating Legitimate Tools
Tech News

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools

By Viral Trending Content 4 Min Read
Share
SHARE

Dec 19, 2024Ravie LakshmananSupply Chain / Software Security

Malicious npm Libraries

Threat actors have been observed uploading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node that have racked up thousands of downloads on the package registry.

The counterfeit versions, named @typescript_eslinter/eslint and types-node, are engineered to download a trojan and retrieve second-stage payloads, respectively.

“While typosquatting attacks are hardly new, the effort spent by nefarious actors on these two libraries to pass them off as legitimate is noteworthy,” Sonatype’s Ax Sharma said in an analysis published Wednesday.

“Furthermore, the high download counts for packages like “types-node” are signs that point to both some developers possibly falling for these typosquats, and threat actors artificially inflating these counts to boost the trustworthiness of their malicious components.”

The npm listing for @typescript_eslinter/eslint, Sonatype’s analysis revealed, points to a phony GitHub repository that was set up by an account named “typescript-eslinter,” which was created on November 29, 2024. Present with this package is a file named “prettier.bat.”

Cybersecurity

Another package linked to the same npm/GitHub account is named @typescript_eslinter/prettier. It impersonates a well-known code formatter tool of the same name, but, in reality, is configured to install the fake @typescript_eslinter/eslint library.

The malicious library contains code to drop “prettier.bat” into a temporary directory and add it to the Windows Startup folder so that it’s automatically run every time the machine is rebooted.

“Far from being a ‘batch’ file though, the “prettier.bat” file is actually a Windows executable (.exe) that has previously been flagged as a trojan and dropper on VirusTotal,” Sharma said.

On the other hand, the second package, types-node, incorporates to reach out to a Pastebin URL and fetch scripts that are responsible for running a malicious executable that’s deceptively named “npm.exe.”

“The case highlights a pressing need for improved supply chain security measures and greater vigilance in monitoring third-party software registry developers,” Sharma said.

The development comes as ReversingLabs identified several malicious extensions that were initially detected in the Visual Studio Code (VSCode) Marketplace in October 2024, a month after which one additional package emerged in the npm registry. The package attracted a total of 399 downloads.

The list of rogue VSCode extensions, now removed from the store, is below –

  • EVM.Blockchain-Toolkit
  • VoiceMod.VoiceMod
  • ZoomVideoCommunications.Zoom
  • ZoomINC.Zoom-Workplace
  • Ethereum.SoliditySupport
  • ZoomWorkspace.Zoom
  • ethereumorg.Solidity-Language-for-Ethereum
  • VitalikButerin.Solidity-Ethereum
  • SolidityFoundation.Solidity-Ethereum
  • EthereumFoundation.Solidity-Language-for-Ethereum
  • SOLIDITY.Solidity-Language
  • GavinWood.SolidityLang
  • EthereumFoundation.Solidity-for-Ethereum-Language
Cybersecurity

“The campaign started with targeting of the crypto community, but by the end of October, extensions published were mostly impersonating the Zoom application,” ReversingLabs researcher Lucija Valentić said. “And each malicious extension published was more sophisticated than the last.”

All the extensions as well as the npm package have been found to include obfuscated JavaScript code, acting as a downloader for a second-stage payload from a remote server. The exact nature of the payload is currently not known.

The findings once again emphasize the need for exercising caution when it comes to downloading tools and libraries from open-source systems and avoid introducing malicious code as a dependency in a larger project.

“The possibility of installing plugins and extending functionality of IDEs makes them very attractive targets for malicious actors,” Valentić said. “VSCode extensions are often overlooked as a security risk when installing in an IDE, but the compromise of an IDE can be a landing point for further compromise of the development cycle in the enterprise.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Gemini 3 vs GPT-5 Pro: Coding, Math, Benchmarks & Creative Tests

New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT

‘Powerful AI is now changing what it means to be good at your work’

OnePlus 15 is Wake-up Call that Apple & Samsung Should Not Ignore

A Collision With Space Debris Leaves 3 Chinese Astronauts Stranded in Orbit

TAGGED: Cyber Security, Internet, JavaScript, Malware, NPM, Supply Chain Security, Trojan, typosquatting, Vscode
Share This Article
Facebook Twitter Copy Link
Previous Article GamingBolt’s Game of the Year – Top 30 Games of 2024
Next Article Who Is Sydney Sweeney Dating? Meet Her Fiancé Jonathan Davino & Ex-Boyfriends
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Ukraine signs deal with France for 100 Rafale jets and air defence systems
World News
Future with U: Phemex celebrates its 6th anniversary with 66% user growth and shared vision
Crypto
Fallout 4 Anniversary Edition is a Mess That Could Have Been Avoided
Gaming News
Google parent Alphabet shares jump 5% after Berkshire Hathaway makes rare tech bet with $4.9 billion stake
Business
Ethereum Treasuries In Trouble: 65% Of Firms Under mNAV
Crypto
Lost Bach pieces performed for first time in 320 years
World News
Gemini 3 vs GPT-5 Pro: Coding, Math, Benchmarks & Creative Tests
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Ukraine signs deal with France for 100 Rafale jets and air defence systems

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Ukraine signs deal with France for 100 Rafale jets and air defence systems
November 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?