More than 70 Harmful npm and VS Code Packages Discovered Harvesting Data and Cryptocurrency

More than 70 Harmful npm and VS Code Packages Discovered Harvesting Data and Cryptocurrency

Introduction

Recently, over 60 malicious npm packages were discovered, posing significant risks to IT infrastructure. Published under three now-removed accounts, these packages have impacted thousands of users by harvesting sensitive system details.

Key Details

  • Who: Discovered by Socket security researcher Kirill Boychenko.
  • What: Malicious packages that stealthily collect system information—hostnames, IPs, DNS servers—while circumventing virtual environment checks.
  • When: Published within an 11-day period and collectively downloaded over 3,000 times.
  • Where: npm package registry, affecting users across Windows, macOS, and Linux.
  • Why: The malicious code can identify high-value targets within networks, making it valuable for hostile actors.
  • How: The install-time script triggers during the npm install, transmitting harvested data to a Discord-controlled endpoint.

Why It Matters

This attack highlights growing vulnerabilities in software supply chains, particularly with npm packages, which are integral to modern development practices. Key areas impacted include:

  • Enterprise Security: Heightened risks around unwanted data exposure and targeted attacks.
  • Cloud Adoption: Organizations leveraging GitHub and npm must enforce stricter usage protocols.
  • Development Practices: Increased scrutiny and validation of third-party packages are now essential.

Takeaway for IT Teams

IT professionals should audit their npm dependencies and establish policies for monitoring package sources. Consider implementing tools for enhanced visibility and security in open-source package usage to mitigate risks.

For more curated news and infrastructure insights, visit TrendInfra.com.

Meena Kande

meenakande

Hey there! I’m a proud mom to a wonderful son, a coffee enthusiast ☕, and a cheerful techie who loves turning complex ideas into practical solutions. With 14 years in IT infrastructure, I specialize in VMware, Veeam, Cohesity, NetApp, VAST Data, Dell EMC, Linux, and Windows. I’m also passionate about automation using Ansible, Bash, and PowerShell. At Trendinfra, I write about the infrastructure behind AI — exploring what it really takes to support modern AI use cases. I believe in keeping things simple, useful, and just a little fun along the way

Leave a Reply

Your email address will not be published. Required fields are marked *