Malicious npm package targets AWS users
ID: b9c6f5ae-9f65-59b6-b2fb-a8e81e000de9
STIX ID: report--b9c6f5ae-9f65-59b6-b2fb-a8e81e000de9
Feed Name: ReversingLabs Blog
ReversingLabs researchers discovered a typosquatting npm package (legacyreact-aws-s3-typescript) that appeared legitimate but contained a postinstall script which downloaded an ELF backdoor; the payload opened a socket to 91.238.181.250 and provided a remote /bin/sh. The report describes the package's publication timeline (clean initial versions, briefly published malicious updates, then a persistent malicious 1.2.4), demonstrates software-supply-chain and typosquatting risks, and introduces Spectra Assure Community as a tool to surface such malicious or suspicious packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
