logo

Malicious npm package targets AWS users

ID: b9c6f5ae-9f65-59b6-b2fb-a8e81e000de9

STIX ID: report--b9c6f5ae-9f65-59b6-b2fb-a8e81e000de9

Feed Name: ReversingLabs Blog

Threat Score
72/100

Date Published: 2024-06-26

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

ReversingLabs researchers discovered a typosquatting npm package (legacyreact-aws-s3-typescript) that appeared legitimate but contained a postinstall script which downloaded an ELF backdoor; the payload opened a socket to 91.238.181.250 and provided a remote /bin/sh. The report describes the package's publication timeline (clean initial versions, briefly published malicious updates, then a persistent malicious 1.2.4), demonstrates software-supply-chain and typosquatting risks, and introduces Spectra Assure Community as a tool to surface such malicious or suspicious packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.