A threat actor has deployed four malicious npm packages using leaked Shai-Hulud malware source code, originally attributed to the TeamPCP hacker group. The packages use typosquatting to target Axios users and steal developer credentials, secrets, cryptocurrency wallet data, and cloud configuration files. One package also includes DDoS botnet functionality supporting HTTP, TCP, and UDP floods. Discovered by OXsecurity, the packages had a combined 2,678 downloads. Stolen credentials are exfiltrated to a C2 server and uploaded to auto-generated public GitHub repositories. Developers who downloaded the affected packages are advised to remove them immediately and rotate all credentials and API keys.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
163 Impressions