NPM users have warned that dozens of malicious packages aim to steal host and network data


  • Take found 60 malicious NPM packages
  • Legitimate packages has usurped in malicious software
  • He was capable of exfiltrating sensitive data

Socket cybersecurity researchers warned against several malicious packages hosted on NPM, stealing sensitive user data and relaying them to attackers.

In a blog article, Socket said that he had identified 60 packages on NPM, which were downloaded from May 12, using three separate accounts. The packages contained a post-install script that runs during “NPM Install” and exfiltrates host names, internal IP addresses, user domestic directories, current work repertoires, user names and DNS system servers.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top