I wish more developers understood the constant stream of malware that is posted to npm, PyPI, and all package managers...
Here's just a taste of some crazy malware Socket identified in the past couple weeks...
All malware descriptions were FULLY WRITTEN by Socket AI.
This code is using curl to send the contents of the file '/etc/passwd' to a remote server. This is a highly suspicious and potentially malicious behavior as it could cause sensitive data to be sent to an attacker's server.
https://t.co/yaxVgzpZEnsocket.dev/npm/package/se…
The script collects a wide range of information from the user's system, including OS details, network interfaces, and SSH files, and sends it to a remote server via DNS queries.
https://t.co/M7FVhL2kEOsocket.dev/npm/package/@u…
The script is using 'curl' to download a Perl script from an external source and then execute it using 'perl'. This behavior is considered highly suspicious and may indicate that a malicious actor is trying to execute code on the system.
https://t.co/02coE3jNMAsocket.dev/npm/package/fi…
The script creates a reverse shell, connecting the user's system to a remote IP address, and potentially sends data to an external server, posing a significant security risk.
https://t.co/k1izLodbnrsocket.dev/npm/package/12…
The script is obfuscated and dynamically creates functions to collect the user's environment variables and sends them to a remote server.
https://t.co/0DIquPJuhtsocket.dev/npm/package/li…
The script is running a PowerShell command with a hidden window and an encoded command. This behavior is considered suspicious and could potentially execute malicious code on the system.
https://t.co/kYT0gdkBGdsocket.dev/npm/package/py…
This code is malicious and should not be used. Remove it from any system on which it is installed immediately. The remote server should be investigated to determine its legitimacy.
https://t.co/vrjugOkw2Dsocket.dev/npm/package/js…
This code is highly suspicious and should not be used without further investigation. The code is heavily obfuscated and could potentially contain malicious code. The purpose of the code is unclear and further investigation is necessary [...].
https://t.co/HTXVthFl1osocket.dev/npm/package/ko…
The code appears to be downloading content from an unknown URL, writing it to a file, and potentially executing it. [...] This code should be reviewed and potentially removed.
https://t.co/pDo5ahfI0Fsocket.dev/npm/package/ya…
@scottinallcaps If interested, you can book time here: socket.dev/demo
Protect your codebase from malicious dependencies by installing Socket in 2 clicks: socket.dev
Share this Scrolly Tale with your friends.
A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.