AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Slashdot  <--  <--- Return to Home Page
   Local Database  Slashdot   [191 / 234] RSS
 From   To   Subject   Date/Time 
Message   VRSS    All   Destructive Malware Available In NPM Repo Went Unnoticed For 2 Y   May 22, 2025
 5:20 PM  

Feed: Slashdot
Feed Link: https://slashdot.org/
---

Title: Destructive Malware Available In NPM Repo Went Unnoticed For 2 Years

Link: https://yro.slashdot.org/story/25/05/22/20122...

An anonymous reader quotes a report from Ars Technica: Researchers have found
malicious software that received more than 6,000 downloads from the NPM
repository over a two-year span, in yet another discovery showing the hidden
threats users of such open source archives face. Eight packages using names
that closely mimicked those of widely used legitimate packages contained
destructive payloads designed to corrupt or delete important data and crash
systems, Kush Pandya, a researcher at security firm Socket, reported
Thursday. The packages have been available for download for more than two
years and accrued roughly 6,200 downloads over that time. "What makes this
campaign particularly concerning is the diversity of attack vectors -- from
subtle data corruption to aggressive system shutdowns and file deletion,"
Pandya wrote. "The packages were designed to target different parts of the
JavaScript ecosystem with varied tactics." [...] Some of the payloads were
limited to detonate only on specific dates in 2023, but in some cases a phase
that was scheduled to begin in July of that year was given no termination
date. Pandya said that means the threat remains persistent, although in an
email he also wrote: "Since all activation dates have passed (June 2023-
August 2024), any developer following normal package usage today would
immediately trigger destructive payloads including system shutdowns, file
deletion, and JavaScript prototype corruption." The list of malicious
packages included js-bomb, js-hood, vite-plugin-bomb-extend, vite-plugin-
bomb, vite-plugin-react-extend, vite-plugin-vue-extend, vue-plugin-bomb, and
quill-image-downloader.

Read more of this story at Slashdot.

---
VRSS v2.1.180528
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Slashdot  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0141 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2025 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224