Malicious npm package targets AWS users
Essential information
- Published
- 27/06/2024 07:58
- Modified
- 27/06/2024 09:26
- Tags
- 2024-06-27 aws backdoor npm supply-chain
- Related entities
- 3 observables, 5 techniques (mitre), 1 malware
Description
ReversingLabs' researchers discovered a malicious package named legacyreact-aws-s3-typescript on the npm repository. It mimicked a popular legitimate package, react-aws-s3-typescript, designed to facilitate file uploads to Amazon S3 Buckets. Initially, the package appeared benign, but a later version included a postinstall script that downloaded and executed a backdoor payload. The package's history demonstrates the challenges of monitoring open source repositories for threats, and RL introduced Spectra Assure Community to help developers assess package risks.