logo

Malicious npm Packages Found Using Image Files to Hide Backdoor Code

ID: 3b2470e6-7bf8-5345-a85a-d5b5e5be7533

STIX ID: report--3b2470e6-7bf8-5345-a85a-d5b5e5be7533

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-07-16

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers discovered two malicious npm packages (img-aws-s3-object-multipart-copy and legacyaws-s3-object-multipart-copy) that impersonated a legitimate library and included altered installation code to run a JavaScript backdoor (loadformat.js). The backdoor decodes malicious content hidden in images (using Microsoft’s logo image), registers the client with a C2 server, polls for attacker commands every five seconds, executes them, and exfiltrates output to a remote endpoint; both packages were subsequently removed by npm.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.