Top Malicious npm Packages Targeting Open Source Projects
Open Source Attacks on the Rise: Top 8 Malicious Packages Found in npm
June 08, 2021
By Ax Sharma
I get asked often what Sonatype's automated malware detection system, Release Integrity, has found so far. Great question.
Back in 2019, Sonatype announced the release of its new technology with early warning capabilities to find malicious releases of open source components, known as "counterfeit components." Release Integrity is part of next-gen Sonatype Intelligence, detecting and blocking their use within modern software factories. We knew then that the future of open source security was changing, and the past year shows just how right we were.
Since then, this technology has repeatedly identified novel malware including those missed by leading antivirus engines, lurking in open source components. With it, Sonatype was the first and only company to proactively catch the dependency or namespace confusion PoC research packages from Alex Birsan when they first sprung up in 2020.
Using automated malware detection systems, the service flagged Birsan's packages in early 2020 as malware. This vulnerability was revealed as promised, affecting more than 35 organizations, including major software companies like Microsoft, Uber, Tesla, Yelp, and Shopify.
At publish date, we have identified upwards of 12,000 suspicious and malicious npm packages.
This figure includes packages infiltrating npm that emerged this year, including:
- Novel malware, typosquatting, and brandjacking.
- Hundreds of original dependency confusion PoCs.
- Thousands of dependency hijacking copycats, malicious and otherwise.
- Bug bounties and contributions by security researchers and infosec activists.
Today we roundup popular malware that Sonatype's Release Integrity has identified thus far, which is by no means an exhaustive list:
Web-browserify
In April of this year, Sonatype's Release Integrity spotted a rather unique macOS and Linux malware sample published to the npm registry, targeting developers.- Existing in the brandjacking npm package "web-browserify," the malware imitated the legitimate "browserify" component that receives over 1.3 million weekly downloads on npm alone.
- The package seems to be specifically designed to target individual NodeJS developers.
Malware named after popular company repos
In March, we first identified malicious dependency confusion packages that were named after repositories, namespaces, or components used by companies such as Amazon, Zillow, Lyft, and Slack.- These packages were:
- amzn
- zg-rentals
- lyft-dataset-sdk
- serverless-slack-app
- These packages were:
5,000+ vigilante activism packages flood npm and PyPI
Earlier this year and shortly after dependency confusion news broke, entities began flooding npm and PyPI with copycat packages. Some of these packages were malicious.- Sonatype's Release Integrity spotted 1,500+ dependency confusion npm packages posted by a vigilante actor to spread awareness about risks of supply chain attacks.
Malware containing njRAT/Bladabindi Trojan
Over the Thanksgiving weekend in 2020, Sonatype discovered another novel malware within the npm registry.- The malicious packages were:
- jdb.js
- db-json.js
- The malicious packages were:
CursedGrabber malware campaign
In November 2020, Sonatype spotted a whole new family of Discord-stealing malware written in C#. The attack even attempted to retrieve and exfiltrate user's payment and billing information from their Discord account.Successor to "Fallguys" malware
In September 2020, ZDNet reported on malware pretending to be a video game's API. The malicious component "fallguys" lived on npm downloads."Twilio-npm"
The malicious npm package described in last year's report tricked Twilio developers with a single-file malware that spawned a reverse shell on the developer's system.Electorn
The misspelled "electorn" package was Sonatype's first newsworthy finding from Release Integrity. The program targeted developers seeking the legitimate and hugely popular Electron library via typosquatting.
Thousands of Components Spotted Thus Far, and Counting
These are just a few examples of suspicious components that Release Integrity has flagged thus far.