Researchers Uncover RAT-Dropping npm Package Targeting Gulp Users
ID: 3bd7fae4-181e-57ff-8cb8-b130bab192ea
STIX ID: report--3bd7fae4-181e-57ff-8cb8-b130bab192ea
Feed Name: The Hacker News
Threat Score
Researchers discovered a malicious npm package, glup-debugger-log, that masquerades as a gulp logger and has been downloaded ~175 times. The package contains obfuscated scripts that perform environmental checks (Windows NT, network interfaces, Desktop item count) to avoid VMs, download additional malware, and establish persistence by launching an HTTP server on port 3004 to receive and execute commands, effectively providing RAT capabilities to attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
