Malicious npm Packages Found Using Image Files to Hide Backdoor Code
ID: 3b2470e6-7bf8-5345-a85a-d5b5e5be7533
STIX ID: report--3b2470e6-7bf8-5345-a85a-d5b5e5be7533
Feed Name: The Hacker News
Cybersecurity researchers discovered two malicious npm packages (img-aws-s3-object-multipart-copy and legacyaws-s3-object-multipart-copy) that impersonated a legitimate library and included altered installation code to run a JavaScript backdoor (loadformat.js). The backdoor decodes malicious content hidden in images (using Microsoft’s logo image), registers the client with a C2 server, polls for attacker commands every five seconds, executes them, and exfiltrates output to a remote endpoint; both packages were subsequently removed by npm.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
