Automatically translated.View original post

Four npm packages were found. Data theft malware was tucked.

Four npm packages, data theft malware and Phantom Bot were found.

According to a report by the website, The Hacker News has mentioned the detection of malware types that steal data from the victim's machine, or Infostealer, and malware types that convert the victim's machine into one of the larger attack networks, or Botnet lurking in up to 4 NPM packages. All 4 packages are listed as follows:

Chalk-tempalte (825 downloads)

@ deadcode09284814 / axios-util (284 downloads)

Axois-utils (963 downloads)

Color-style-utils (934 downloads)

According to a research team from OX Security, an expert in cybersecurity management, the four have different hidden malware:

Axois-utils has a Botnet malware written in the Golang language called Phantom Bot. This malware has the ability to use the victim machine as one of the larger system attack networks to crash by means of DDoS (Distribution Denial-of-Service) with Flood targeted websites through HTTP, TCP, and UDP protocols. In addition, the malware has the ability to persevere on the victim's system by placing malware files (Payload) in the Windows Startup folder.

Chalk-tempalte embeds Infostealer malware. Clone malware comes from Shai-Hulud Worm. Infostealer malware that can spread itself to other software packages of developers whose machines are embedded by seizing the developer's account (Developer Account) and embedding itself into every package. This is a supply chain attack or Supply Chain Attack. This malware is also called Self-Propagating Software Supply Chain Malware. As for the ability to steal data, all data is sent to the C2 control server (Command Control). Located at 87e0bbc636999b.lhr [.] life.

"@ deadcode09284814 / axios-util" and "color-style-utils" will be Infostealer malware with data theft functions similar to others, such as the ability to steal passwords for cloud access, SSH keys, environment variables, victim system information, IP number, and Crypto Wallet information, and then send them to C2 servers located on "80.200.28 [28: 2222" and "edcf8b03c84634.lhr [.] life," respectively.

The research team recommends that if any reader has accidentally downloaded these packages and installed them, check for Configuration settings on IDEs and Coding Agents such as Claude Code and delete them, change Secrets, and check Repo on the Github that the reader is using to find out if there is a malware string value "A Mini Sha 1-Hulud has Appeared" and immediately block suspected malware-related domains.

# Trending # Lemon 8 Howtoo # lemon 8 diary # npm # freedomhack

6/11 Edited to

... Read moreจากประสบการณ์ใช้งาน npm ในการพัฒนาโปรเจ็กต์ ผมเห็นชัดว่าสิ่งที่เพิ่มความเสี่ยงต่อความปลอดภัยของระบบโปรแกรมเมอร์ คือการติดตั้งแพ็กเกจที่ไม่ได้รับการตรวจสอบอย่างรอบคอบ เพราะแพ็กเกจเหล่านี้อาจแฝงมัลแวร์ เช่นเดียวกับกรณีแพ็กเกจ npm 4 ตัวที่ถูกค้นพบว่าซุกซ่อนมัลแวร์ Infostealer และ Botnet Phantom Bot เครื่องมือเหล่านี้ไม่เพียงแต่ขโมยข้อมูลจากเครื่องผู้ใช้ เช่น รหัสผ่าน SSH, คีย์ API หรือแม้แต่ข้อมูลกระเป๋าเงินคริปโต แต่ยังสามารถสั่งให้เครื่องผู้ใช้กลายเป็นส่วนหนึ่งของเครือข่ายโจมตีแบบ DDoS ได้อีกด้วย เครื่องมือมัลแวร์ Phantom Bot ที่เขียนด้วยภาษา Go นี้สามารถฝังตัวเองในโฟลเดอร์ Windows Startup เพื่อความทนทานต่อการลบหรือรีบูตเครื่อง ผมแนะนำว่าเมื่อพบว่าติดตั้งแพ็กเกจที่น่าสงสัยไปแล้วควรลบแพ็กเกจนั้นทันทีและตรวจสอบการตั้งค่าของ IDE ที่ใช้อยู่ เช่น การลบค่า configuration ที่เชื่อมต่อกับแพ็กเกจเหล่านั้น และเปลี่ยนรหัสลับ (secrets) ที่อาจถูกขโมยไป นอกจากนี้ควรสแกน repo บน GitHub หรือที่เก็บซอร์สโค้ดอื่นๆ เพื่อหาสตริงเด็ดขาดอย่าง "A Mini Sha1-Hulud has Appeared" ซึ่งเป็นสัญญาณว่ามัลแวร์ได้แฝงตัวและแพร่กระจายไปแล้ว เนื่องจากมัลแวร์ Infostealer หรือการโจมตีห่วงโซ่อุปทาน (Supply Chain Attack) ทำให้แพ็กเกจหนึ่งแพร่ไปยังแพ็กเกจอื่นๆ ได้ ผมขอแนะนำให้พยายามใช้แพคเกจจากแหล่งที่มีความน่าเชื่อถือสูง และหมั่นติดตามข่าวสารจากหน่วยงานความปลอดภัยไซเบอร์เป็นระยะๆ เพื่อป้องกันการตกเป็นเหยื่อของมัลแวร์ในลักษณะนี้ สุดท้าย การบล็อกโดเมนที่น่าสงสัยที่ใช้ควบคุมมัลแวร์ เช่น 87e0bbc636999b.lhr.life หรือ 80.200.28.28:2222 เป็นอีกหนึ่งวิธีที่ช่วยลดความเสียหาย สรุปว่าการรักษาความปลอดภัยในการใช้แหล่งซอฟต์แวร์เสริม (packages) ต้องคำนึงถึงความปลอดภัยอย่างรัดกุมและไม่ประมาท