# Malware Monthly - November 2022

**December 15, 2022**  
By Sonatype Developer Relations

18 minute read time

Welcome to the first edition of Malware Monthly, where our teams of security researchers and developer advocates bring you the latest information on malicious and suspicious packages discovered in software registries.

As developers, it is important to stay informed about the latest security vulnerabilities and threats to keep your build environments protected. This monthly publication aims to provide you with the information and insights you need to stay one step ahead of the bad actors and keep your projects safe.

For this November 2022 edition of Malware Monthly, our security researchers discovered and analyzed nearly 350 packages flagged as malicious, suspicious, or dependency confusion proof-of-concepts in PyPI and npm registries. Also, we dug a little deeper into two discovered packages.

Additionally, [we explored what an exploit against the OpenSSL vulnerabilities](/content/blog/what-the-openssl-vulnerabilities-are-and-arent/index.html) could do and how dependency management could resolve the issues.

## The Ones That Caught Our Attention  
We discovered packages such as _tshawn-lrce_ and _tshawn-wrce_ that are tainted with malicious reverse shell and bind shell scripts.

If you're unfamiliar with these techniques, think of a reverse shell as a setup where:

- An attacker starts a server instance on the target machine.
- The target downloads and inadvertently executes the malicious packages in their build environment.
- The target machine becomes a client that connects to the attacker's server.
- The attacker gains access to the target machine and can execute commands.

Bind shells are similar in that they also establish a backdoor connection between the attacker and the target, but in this case, they create an open port on the target machine, instead of establishing a connection from the target to the attacker. With an opened port, the attacker can execute commands on the target machine.

Other packages our security researchers found, such as _requests-dm_, _fastupdate_, and _discordxyz,_ look for information on the target computer's OS, such as hostnames, IPs, credentials, and other configuration details, with the purpose of exfiltrating such data to malicious servers.

## A Deeper Dive into pywx  
Another package worth mentioning is _pywx._ With a modus operandi similar to other packages disclosed [by Phylum](https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack), this one uses a similar attack methodology. Our security researchers noticed that it starts by copying a legit package, in this case, _object_pool_, and sneakily injects an **__import__** statement to run malicious code from an external source.

Let's break it down a little further.

By looking at _setup.py_ in _pywx_, you might think there's nothing strange about the code. And even though the fields are almost identical to the original _setup.py_ in _object_pool_ (same author, same email, same license), there's no malicious code in sight so far:

But when you zoom out the code editor window for _setup.py_ in _pywx_, you'll find the code is not as innocent as it looked at first glance: a malicious **__import__** injection is offset by 321 spaces:

## The Hidden __import__  
If we turn on word wrapping, the malicious code looks like this:

And after decoding the Base64 encoded string, we find the following Python script:

The script creates a temporary file and stores it in a variable with the same name. Then, it writes code to the temporary file and attempts to run it by passing it to the "_ssystem" function, along with a string that specifies the command to execute the file.

[As Phylum pointed out](https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack), threat actors often run the script with _pythonw.exe_ instead of _python.exe_ to avoid opening a console window and keep code execution hidden from the user. The purpose of this payload is to download and execute malicious code from a remote URL.

## Other Malicious Packages Caught by Sonatype  
We caught the following in November via Sonatype's [automated malware detection system](/content/products/intelligence/index.html), offered as part of [Sonatype Firewall](/content/products/sonatype-repository-firewall/index.html):

_121block-pattern-explorer_  
_23872387a-bait_  
_@aviationpast/niotest_  
_@ccms/verify_  
_@core-pas/cyb-core_  
_@dbk-legacy/muster_  
_@dbk-legacy/roster-modules-ebanking_  
_@ebx-auth/ebx-clientauth-frontend-sdk_  
_@filkers/filkersjs-model_  
_@focuson/lenstest_  
_@geocomponents/hooks_  
_@geocomponents/reducers_  
_@gwen001/utest_  
_@malware-test-aguti-babas-thete-amass/test-mlw3-aguti-babas-thete-amass_  
_@malware-test-beech-bobac-cards-emote/test-mlw3-beech-bobac-cards-emote_  
_@malware-test-bunya-botch-betid-grind/test-mlw3-bunya-botch-betid-grind_  
_@malware-test-chota-scows-bulky-durra/test-mlw3-chota-scows-bulky-durra_  
_@malware-test-doves-ileum-griot-manto/test-mlw3-doves-ileum-griot-manto_  
_@malware-test-frows-spaes-whips-hable/test-mlw3-frows-spaes-whips-hable_  
_@malware-test-golem-brave-oculi-durum/test-mlw3-golem-brave-oculi-durum_  
_@malware-test-greve-telic-gilly-aheap/test-mlw3-greve-telic-gilly-aheap_  
_@malware-test-jnana-rifle-inter-cymes/test-mlw3-jnana-rifle-inter-cymes_  
_@malware-test-pareu-neigh-proos-blind/test-mlw3-pareu-neigh-proos-blind_  
_@malware-test-squib-crimp-yenta-namer/test-mlw3-squib-crimp-yenta-namer_  
_@malware-test-stomp-dearn-longe-voice/test-mlw3-stomp-dearn-longe-voice_  
_@michaljaz/backdoor_  
_@nelio-content/components_  
_@nelio-content/data_  
_@nelio-content/date_  
_@nelio-content/edit-post_  
_@nelio-content/networks_  
_@nelio-content/post-quick-editor_  
_@nelio-content/social-message-editor_  
_@nelio-content/task-editor_  
_@nelio-content/types_  
_@nelio-content/utils_  
_@orlserg32112/socket-test-vulndep_  
_@shipping-places-ui-library/qr-reader_  
_@sid0krypt/dompubsub_  
_@test-vue-docgen/mixins_  
_@unifly-aero/web-common_  
_@upc2web/font-firasans_  
_@vendavo/not-pezzi_  
_addon-kit_  
_angular-mep_  
_apch_  
_api-devices_  
_app_assets_  
_xxx-libagent-napi_* intentionally redacted to protect the target  
_xxx-native_* intentionally redacted to protect the target  
_aspnet-asset-management_  
_athos-player_  
_auo_  
_auth0-authorisation-to-s3_  
_aws-subnet-resolver-plugin_  
_azure-sdk-tools_  
_b2b_  
_babel-preset-geocaching_  
_bancolombia-devex-angular_  
_bbq-123-npm-test_  
_bc-demo_  
_bc-tabs_  
_bdapp_  
_bi3g0-npm-test_  
_biolife-core_  
_block-pattern-explorer_  
_blockchain-models-ts_  
_bluehost-wordpress-plugin_  
_bonsoird-test-v1_  
_bootstrap-v4_  
_bootstrap-v5_  
_bot-discord-js_  
_btoocore_  
_cdd-vault_  
_charset-normalizer_  
_cloudwatch2slack_  
_cnscode_  
_cnscodes_  
_color-random_  
_color-utility_  
_color-utility-test_  
_coloram_  
_coloriv_  
_colors-it_  
_colorwed_  
_commerce-sdk-react_  
_consul-acls_  
_consul-hcp_  
_consul-partitions_  
_copy-webpack-plugin-v6_  
_core-argos-litelement-artifact_  
_core-guest-loop-routes_  
_cp-proxy_  
_cryptography-ts_  
_cs_kid_  
_cvs-codestyle_  
_cvs-components_  
_d2-collection_  
_d3-dbk_  
_dbk-legacy_  
_Deepmountains-lrce_  
_delaware_  
_demopaxkhimkus_  
_dependency-conf_  
_deshine_  
_devicespoof_  
_devicespoofer_  
_dgctl_  
_Discord-Embedds_  
_discordies_  
_discordxyz_  
_discourse-common_  
_discourse-ensure-deprecation-order_  
_dvf-utils_  
_eclipse-megamovie_  
_edit_session_  
_ehss-angularjs-shared_  
_elasticsearch-py_  
_elasticsearch-py.tar.gz_  
_emu-plus_  
_engine.io-client-v3_  
_erc1400_  
_esperamier_  
_estimating_  
_execList_  
_executeListener_  
_fastupdate_  
_faustwp-cli_  
_faustwp-core_  
_fca-horizon-remake_  
_fe-extension_  
_firefly-utilities-js_  
_fms-test-bbb_  
_forgejs-samples_  
_gcp-dependency_  
_geocaching-express-account-middleware_  
_geocomponents_  
_ggvpslmao_  
_go-requests_  
_gulp.utils_  
_gunship_  
_harel-health-check_  
_harel-logger-ts_  
_harel-token-ts_  
_hdwallet-sandbox_  
_hello-world-target_  
_helm-binary-testing_  
_hemoabsihh12_  
_hisdhus_  
_hosseinc_  
_hosseinp_  
_infowrap-filepicker_  
_install-utils_  
_intel-xai-tools_  
_internal-lib-build_  
_ion-lsp-server_  
_io-stream-fx_  
_ipcode_  
_iua_  
_iwasm-ion-schema_  
_jive_web_  
_joqlqwertyxxff_  
_jquery.select2_  
_jquery_ui_checkbowwx_  
_jquery_ui_checkbox_  
_kaaper_  
_kers_  
_kikeappa_  
_knockoutjs_  
_ld-impl-linux-64_  
_librarie_  
_lightgmb_  
_lmaoalmost_  
_loy_  
_mai-pro_  
_man-installer_  
_manda-cv-secureit_  
_manda-tu-cv-a-secureit_  
_mantis-ui_  
_mastercard_ezaccess_for_issuers_api_  
_mc-ui-utils_  
_mianoplmao_  
_mianoplol_  
_mianprojekt_  
_mianprojlol_  
_miantested_  
_miantestedone_  
_miantestone_  
_microsoft-data-mapper-vscode-extension_  
_mozilla_  
_multer-sharp-minio-storage_  
_mxnet-cuXXX_  
_my-npm-dep-confuse_  
_my-npm-fareez1234_  
_nab-chat-widget_  
_nightly_builds_  
_ninja-turtle-oil-spill_  
_node-ffmpeg-win32-ia32_  
_node-ffmpeg-win32-x64_  
_node_resolve_main_  
_node_resolve_main_2_  
_node_resolve_nested_main_  
_nt4PAdyP_  
_object3_  
_oiu_  
_omachihihi_  
_oxeru_  
_package-ions_  
_paintpy_  
_paquete-malicioso_  
_phaseOne_  
_pollitopio_  
_postcss-toc_  
_pranked_  
_privatepkg_  
_pylo-color_  
_pyslqite3_  
_pytroch_  
_pywe_  
_pywx_  
_quarejma-botnet_  
_quarejma-botnetx_  
_quarejma-door_  
_quarejma-erdem_  
_react-native-website-monorepo_  
_react-nesting-example-legacy_  
_remix-run_  
_requests-dm_  
_ripe.atlas.dyndns_  
_robloxtracer_  
_s24-saw_  
_salamus7_  
_sebastestnode_  
_section16_api_  
_seller-base-common_  
_seller-base-service_  
_seller-listing-service_  
_semrush-help-menu_  
_semrush-sso-extended_  
_sgt-build-process_  
_sgt-log_  
_sgt-wp-js-log_  
_shaders_  
_shiluosl-cdn_  
_shopee-ui-react_  
_signiapp_  
_simple-color_  
_sitech-demo31337_  
_sitechdemo100_  
_skywriter_server_  
_sock-1_  
_sock-2_  
_socket-first-level-dep_  
_socket-first-level-dep-1_  
_socket-test-vulnerable_  
_spyMe_  
_stale-props_  
_strip-ansi-v6_  
_styler_  
_su-commons-litelement-artifact_  
_sudo2_  
_syntax_manager_  
_szs-ss_  
_teleport-client_  
_tensrflow_  
_tes1a_  
_test-draco_  
_test-inherited-attrs_  
_test-mlw1-aguti-babas-thete-amass_  
_test-mlw1-avize-quays-sedgy-jiber_  
_test-mlw1-beech-bobac-cards-emote_  
_test-mlw1-chota-scows-bulky-durra_  
_test-mlw1-choux-hunky-nulls-demes_  
_test-mlw1-chuse-roomy-quire-lolly_  
_test-mlw1-dwale-jolts-baron-suave_  
_test-mlw1-fiscs-berks-ahoys-waled_  
_test-mlw1-frows-spaes-whips-hable_  
_test-mlw1-pareu-neigh-proos-blind_  
_test-mlw1-squib-crimp-yenta-namer_  
_test-mlw1-staid-piles-suite-spite_  
_test-mlw1-stamp-humic-puked-trogs_  
_test-mlw1-troke-start-sarod-tiler_  
_test-mlw2-aguti-babas-thete-amass_  
_test-mlw2-aroba-muser-cafes-tints_  
_test-mlw2-beech-bobac-cards-emote_  
_test-mlw2-bunya-botch-betid-grind_  
_test-mlw2-downs-asway-lakhs-caste_  
_test-mlw2-fiscs-berks-ahoys-waled_  
_test-mlw2-golem-brave-oculi-durum_  
_test-mlw2-pareu-neigh-proos-blind_  
_test-mlw2-pinko-jatos-quake-sdein_  
_test-mlw2-sects-prang-fract-await_  
_test-mlw2-stamp-humic-puked-trogs_  
_test1221-npm_  
_testbc_  
_tester40_  
_testpck-npm_  
_tez-wrapper_  
_theme_manager_base_  
_thingsboard-advanced-attribute-widget_  
_tinymce-codemirror_  
_toolbox_expose_  
_trejklfffffffffgdjg_  
_trin-axios_  
_truffle-plugin-stdjsonin_  
_tsa321321ab_  
_tshawn-lrce_  
_tshawn-wrce_  
_tsp-sdk_  
_type-color_  
_typing-extnesions_  
_ul-mailru_  
_ulrlib3_  
_unsafe-test-sc-nr_  
_uploadcare-tinymce_  
_urllb_  
_usefedora_  
_util-internal.js_  
_ux-tracking-utils_  
_vfile5_  
_vue-loader10_  
_vue-loader11_  
_vue-loader12_  
_vue-loader13_  
_vue-loader14_  
_vue-loader15_  
_vue-loader16_  
_vue-loader17_  
_vue-loader18_  
_vue-loader19_  
_vue-loader20_  
_vue-loader21_  
_vue-loader22_  
_vue-loader23_  
_vue-loader24_  
_vue-loader25_  
_vue2-wangwanqi_  
_vulnerablbsusuendency_  
_wangwanqi-tools_  
_web5_  
_webbluetooth-edison-demo_  
_webpack-dev-fixture_  
_webpack-latest_  
_webpack4-1_  
_webpack5-1_  
_wp-shuttle_  
_xamp_  
_xv_chrome_  
_ysu-commons-litelement-artifact_  
_zp-styles_

Since 2019, we've discovered 102,930 packages flagged as malicious, suspicious, or proof of concept. Our next-generation AI behavioral analysis and automated policy enforcement system caught these packages, and our Security Research team confirmed and analyzed these findings.

## How to Protect Your Organization
As uncovered in our 8th annual [_State of the Software Supply Chain_](/content/state-of-the-software-supply-chain/introduction/index.html) report:

"These packages come in many shapes and sizes, but what unifies them is they rarely even pretend to be working code; they exploit the automation that exists in the build or in the dependency managers used by developers, who inadvertently install the malicious code in nanoseconds."

[Malicious software supply chain attacks continue to increase exponentially year over year](/content/state-of-the-software-supply-chain/introduction/index.html). Security threats continue to become more sophisticated. As a DevSecOps organization, we remain committed to identifying and halting attacks, such as those mentioned above, against open source developers and the wider software supply chain.

Users of [Sonatype Firewall](/content/products/sonatype-repository-firewall/index.html) can rest easy knowing that such malicious packages would automatically be blocked from reaching their development builds.

-400x409%20_Optimized.png?width=150&height=150&name=voyage-(1)-400x409%20_Optimized.png)

Written by **Sonatype Developer Relations**

As Sonatype's Developer Relations team, we empower software developers, infosec practitioners, and DevOps/SRE pros to do their best work.
