Telegram Group & Telegram Channel
Тут опять NPM поломали

Starting at September 8th, 13:16 UTC, our Aikido intel feed alerted us to a series packages being pushed to npm, which appeared to contains malicious code. These were 18 very popular packages,

backslash (0.26m downloads per week)
chalk-template (3.9m downloads per week)
supports-hyperlinks (19.2m downloads per week)
has-ansi (12.1m downloads per week)
simple-swizzle (26.26m downloads per week)
color-string (27.48m downloads per week)
error-ex (47.17m downloads per week)
color-name (191.71m downloads per week)
is-arrayish (73.8m downloads per week)
slice-ansi (59.8m downloads per week)
color-convert (193.5m downloads per week)
wrap-ansi (197.99m downloads per week)
ansi-regex (243.64m downloads per week)
supports-color (287.1m downloads per week)
strip-ansi (261.17m downloads per week)
chalk (299.99m downloads per week)
debug (357.6m downloads per week)
ansi-styles (371.41m downloads per week)

All together, these packages have more than 2 billion downloads per week.

npm debug and chalk packages compromised
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised

Был подсунут обфусцированный код, который перехватывал трафик

> This malware is essentially a browser-based interceptor that hijacks both network traffic and application APIs. It injects itself into functions like fetch, XMLHttpRequest, and common wallet interfaces, then silently rewrites values in requests and responses.

Украли доступ через фишинг у одного мантейнера
https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydje4zqis2y

В статье утверждается, что похожей атаке подвергся и мантейнер других пакетов

Таблицу с версиями пакетов прикрепил к посту

Дополнительные ссылки почитать

We Just Found Malicious Code in the Popular NPM Package
https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the

https://news.ycombinator.com/item?id=45169657

npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack
https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack

Issue
https://github.com/chalk/chalk/issues/656
https://github.com/debug-js/debug/issues/1005#issuecomment-3266885191

Что бы проверить нет ли в ваших зависимостях гадости

$ rg -uu --max-columns=80 --glob '*.js' _0x112fa8
16👍7



group-telegram.com/parrotontheweb/511
Create:
Last Update:

Тут опять NPM поломали

Starting at September 8th, 13:16 UTC, our Aikido intel feed alerted us to a series packages being pushed to npm, which appeared to contains malicious code. These were 18 very popular packages,

backslash (0.26m downloads per week)
chalk-template (3.9m downloads per week)
supports-hyperlinks (19.2m downloads per week)
has-ansi (12.1m downloads per week)
simple-swizzle (26.26m downloads per week)
color-string (27.48m downloads per week)
error-ex (47.17m downloads per week)
color-name (191.71m downloads per week)
is-arrayish (73.8m downloads per week)
slice-ansi (59.8m downloads per week)
color-convert (193.5m downloads per week)
wrap-ansi (197.99m downloads per week)
ansi-regex (243.64m downloads per week)
supports-color (287.1m downloads per week)
strip-ansi (261.17m downloads per week)
chalk (299.99m downloads per week)
debug (357.6m downloads per week)
ansi-styles (371.41m downloads per week)

All together, these packages have more than 2 billion downloads per week.

npm debug and chalk packages compromised
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised

Был подсунут обфусцированный код, который перехватывал трафик

> This malware is essentially a browser-based interceptor that hijacks both network traffic and application APIs. It injects itself into functions like fetch, XMLHttpRequest, and common wallet interfaces, then silently rewrites values in requests and responses.

Украли доступ через фишинг у одного мантейнера
https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydje4zqis2y

В статье утверждается, что похожей атаке подвергся и мантейнер других пакетов

Таблицу с версиями пакетов прикрепил к посту

Дополнительные ссылки почитать

We Just Found Malicious Code in the Popular NPM Package
https://jdstaerk.substack.com/p/we-just-found-malicious-code-in-the

https://news.ycombinator.com/item?id=45169657

npm Author Qix Compromised via Phishing Email in Major Supply Chain Attack
https://socket.dev/blog/npm-author-qix-compromised-in-major-supply-chain-attack

Issue
https://github.com/chalk/chalk/issues/656
https://github.com/debug-js/debug/issues/1005#issuecomment-3266885191

Что бы проверить нет ли в ваших зависимостях гадости

$ rg -uu --max-columns=80 --glob '*.js' _0x112fa8

BY 🦜 on the web





Share with your friend now:
group-telegram.com/parrotontheweb/511

View MORE
Open in Telegram


Telegram | DID YOU KNOW?

Date: |

The company maintains that it cannot act against individual or group chats, which are “private amongst their participants,” but it will respond to requests in relation to sticker sets, channels and bots which are publicly available. During the invasion of Ukraine, Pavel Durov has wrestled with this issue a lot more prominently than he has before. Channels like Donbass Insider and Bellum Acta, as reported by Foreign Policy, started pumping out pro-Russian propaganda as the invasion began. So much so that the Ukrainian National Security and Defense Council issued a statement labeling which accounts are Russian-backed. Ukrainian officials, in potential violation of the Geneva Convention, have shared imagery of dead and captured Russian soldiers on the platform. Telegram, which does little policing of its content, has also became a hub for Russian propaganda and misinformation. Many pro-Kremlin channels have become popular, alongside accounts of journalists and other independent observers. But Kliuchnikov, the Ukranian now in France, said he will use Signal or WhatsApp for sensitive conversations, but questions around privacy on Telegram do not give him pause when it comes to sharing information about the war. On Telegram’s website, it says that Pavel Durov “supports Telegram financially and ideologically while Nikolai (Duvov)’s input is technological.” Currently, the Telegram team is based in Dubai, having moved around from Berlin, London and Singapore after departing Russia. Meanwhile, the company which owns Telegram is registered in the British Virgin Islands. Markets continued to grapple with the economic and corporate earnings implications relating to the Russia-Ukraine conflict. “We have a ton of uncertainty right now,” said Stephanie Link, chief investment strategist and portfolio manager at Hightower Advisors. “We’re dealing with a war, we’re dealing with inflation. We don’t know what it means to earnings.”
from sg


Telegram 🦜 on the web
FROM American