216.73.217.22

Malicious npm package targets AWS users

· Published 27/06/2024 07:58 · Modified 27/06/2024 09:26

Export JSON

Essential information

Published
27/06/2024 07:58
Modified
27/06/2024 09:26
Tags
2024-06-27 aws backdoor npm supply-chain
Related entities
3 observables, 5 techniques (mitre), 1 malware

Description

ReversingLabs' researchers discovered a malicious package named legacyreact--s3-typescript on the repository. It mimicked a popular legitimate package, react--s3-typescript, designed to facilitate file uploads to Amazon S3 Buckets. Initially, the package appeared benign, but a later version included a postinstall script that downloaded and executed a payload. The package's history demonstrates the challenges of monitoring open source repositories for threats, and RL introduced Spectra Assure Community to help developers assess package risks.

External references