216.73.217.22

Malware found on npm infecting local package with reverse shell

· Published 26/03/2025 16:55 · Modified 26/03/2025 17:20

Export JSON

Essential information

Published
26/03/2025 16:55
Modified
26/03/2025 17:20
Tags
2025-03-26 ethers-provider2 ethers-providerz javascript npm package-infection persistence reverse shell
Related entities
1 observables, 11 techniques (mitre)

Description

A sophisticated malware campaign targeting packages has been discovered, involving two malicious packages: and . These packages act as downloaders, hiding their malicious payload cleverly. Upon installation, they patch the legitimate locally-installed package 'ethers' with a new file containing malicious code. This patched file ultimately serves a , connecting to the threat actor's server. The malware employs evasive techniques, maintaining even after removal of the original malicious package. This approach demonstrates a high level of sophistication and poses a significant threat to software supply chain security. The campaign also includes other related packages, highlighting the growing scope of risks for both software producers and end-user organizations.

External references