Friday, March 24, 2023
News - BitSmart.US
No Result
View All Result
  • Home
  • More
No Result
View All Result
News - BitSmart.US
No Result
View All Result

More than 200 cryptomining packages flood npm and PyPI registry

by BitSmart.US
August 22, 2022
in Uncategorized
0
More than 200 cryptomining packages flood npm and PyPI registry
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Sonatype has noticed 186 malicious packages flooding the npm registry at this time. These packages infect Linux hosts with cryptominers by downloading a malicious Bash script from the risk actor’s server through the Bitly URL shortener service. Our discovery follows one other researcher’s discovery of 55 PyPI packages from this week, that additionally pull crypto miners in an an identical vogue from the identical offending URL.

AppSec/API Security 2022

186 counterfeit npm packages drop cryptominers

As we speak, Sonatype’s automated malware detection techniques flagged 186 npm packages that every one impersonate the closely used http-errors JavaScript library that will get downloaded over 50 million instances on a weekly foundation.

The whole listing of 186 packages we recognized is present in this PDF.

All of those packages have been revealed from a pseudonymous npm account referred to as “17b4a931.”

Many of those packages are typosquats and goal customers of recognized libraries like React (typosquat being ‘r2act’) and QT (through ‘qtt’ typosquat).

The index.js file contained inside these packages reveals they’re the truth is pulling the professional ‘http-errors’ library from npm, in order to not elevate eyebrows. However, let’s admit, the names of those packages are drastically completely different from ‘http-errors’ regardless of how spectacular a job they could do in impersonating the venture’s README verbatim.

Scrolling down previous just a few strains of code reveals some sinister exercise:

On Line 115, we see the packages are pulling content material from a Bit.ly URL and silently executing this script whereas muting its output (through >/dev/null).

The developer behind these malicious packages has even left a snarky remark within the code, acknowledging the malware, being a Bash script, would run on Unix-based techniques solely:

“if ur utilizing home windows for putting in this bundle ur 1 fortunate son of a *****”

And the Bit.ly URL redirects to the handle proven under:

https://bit[.]ly/3c2tMTT => http://80.78.25[. (Read more…)



Source link

Related articles

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

The Countdown Begins: One Year to Go Before the Next Bitcoin … – BeInCrypto

March 24, 2023
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Bitcoin and Ethereum: Crypto markets shake off interest rate rises – Proactive Investors UK

March 24, 2023
Tags: Crypto MiningcryptominingfloodnpmPackagesPyPIRegistryUncategorized
Share76Tweet47

Related Posts

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

The Countdown Begins: One Year to Go Before the Next Bitcoin … – BeInCrypto

by BitSmart.US
March 24, 2023
0

The Countdown Begins: One Year to Go Before the Next Bitcoin ...  BeInCrypto Source link

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Bitcoin and Ethereum: Crypto markets shake off interest rate rises – Proactive Investors UK

by BitSmart.US
March 24, 2023
0

Bitcoin and Ethereum: Crypto markets shake off interest rate rises  Proactive Buyers UK Source link

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Privacy Coins on the Rise: Monero (XMR), Zcash (ZEC), Ethereum … – NewsBTC

by BitSmart.US
March 24, 2023
0

Privacy Coins on the Rise: Monero (XMR), Zcash (ZEC), Ethereum ...  NewsBTC Source link

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Dogecoin Mining Revenue Massively Fell In Past 12 Months – NewsBTC

by BitSmart.US
March 24, 2023
0

Dogecoin Mining Revenue Massively Fell In Past 12 Months  NewsBTC Source link

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

8 Top Crypto Picks For Huge 10x Growth in 2023 – Analytics Insight

by BitSmart.US
March 24, 2023
0

8 Top Crypto Picks For Huge 10x Growth in 2023  Analytics Perception Source link

Load More
Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest

Two Tokens That Have The Potential Give You Financial Fruition

0

Could It Be the Future of Money?

0

The Myth and the Reality

0

What Is Bitcoin Transaction Mixing? How Does It Work & Is It Legal?

0
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

The Countdown Begins: One Year to Go Before the Next Bitcoin … – BeInCrypto

March 24, 2023
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Bitcoin and Ethereum: Crypto markets shake off interest rate rises – Proactive Investors UK

March 24, 2023
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Privacy Coins on the Rise: Monero (XMR), Zcash (ZEC), Ethereum … – NewsBTC

March 24, 2023
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Dogecoin Mining Revenue Massively Fell In Past 12 Months – NewsBTC

March 24, 2023

Recent News

Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

The Countdown Begins: One Year to Go Before the Next Bitcoin … – BeInCrypto

March 24, 2023
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Bitcoin and Ethereum: Crypto markets shake off interest rate rises – Proactive Investors UK

March 24, 2023
Litecoin (LTC) Price Prediction for March Is Bearish – BeInCrypto

Privacy Coins on the Rise: Monero (XMR), Zcash (ZEC), Ethereum … – NewsBTC

March 24, 2023

Categories

  • Altcoin
  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Cryptocurrency
  • DeFi
  • Dogecoin
  • Ethereum
  • ICO
  • Litecoin
  • Videos

Contact Us

© 2022 BitSmart Digital Asset Management

No Result
View All Result
  • Home
  • More

© 2022 BitSmart Digital Asset Management