This Week in Malware - Over 100 Packages Discovered | Sonatype

This Week in Malware - Over 100 Packages Discovered

October 07, 2022
By Aaron Linskens

6 minute read time

This week in malware, we discovered and analyzed more than 100 packages flagged as malicious, suspicious, or dependency confusion attacks in npm and PyPI registries.

Malicious Packages Caught by Sonatype

We caught the following this week via Sonatype's automated malware detection system, offered as part of Sonatype Firewall:

  1. 1inch
  2. 4ff-lib-foundation
  3. @malware-test-bises-celts-borel-sneak/test-mlw3-bises-celts-borel-sneak
  4. @malware-test-jelly-poled-trull-tokes/test-mlw3-jelly-poled-trull-tokes
  5. @malware-test-lazar-bales-avows-inkle/test-mlw3-lazar-bales-avows-inkle
  6. @malware-test-merge-agony-whits-blate/test-mlw3-merge-agony-whits-blate
  7. @malware-test-piles-perky-glory-sahib/test-mlw3-piles-perky-glory-sahib
  8. @malware-test-pling-pangs-birks-cubit/test-mlw3-pling-pangs-birks-cubit
  9. @schnux/example
  10. @step-security/malware-simulator
  11. ahahjesus
  12. amitbhai
  13. anis-regex
  14. ansi-ergex
  15. ansi-reegx
  16. ansi-regxe
  17. ansi-rgeex
  18. asni-regex
  19. aynmatch
  20. aypports-color
  21. cis-publishers
  22. cloudflare-plugin-frontend
  23. coveragepublisher
  24. cumul.io-integration
  25. cumul.io-plugin-citybikes
  26. cumul.io-plugin-mysql
  27. d2-collection
  28. darshanno1
  29. dcrdata
  30. demozeel
  31. deubg
  32. dexclient
  33. discord-external
  34. dup-glob
  35. dupport-colors
  36. dypports-color
  37. edbug
  38. esrtaverse
  39. estarverse
  40. estraevrse
  41. estraveres
  42. estravesre
  43. estravrese
  44. estrvaerse
  45. ethereum0etl
  46. ethereum2
  47. etsraverse
  48. xxx-sdk-sample-node
  49. example-gke-workload-identity-app
  50. finn-style
  51. futures-sdk
  52. ginore
  53. glob-aprent
  54. ibiza-universe
  55. ignoer
  56. ignroe
  57. imcromatch
  58. ingore
  59. log-status
  60. mciromatch
  61. micormatch
  62. micrmoatch
  63. micro-ed25519-hdkey
  64. microamtch
  65. micromacth
  66. micromtach
  67. mircomatch
  68. navigator-updatertest
  69. naymatch
  70. pip-foo
  71. predpatt
  72. retrap
  73. setraverse
  74. shopify-marketplaces-admin-app
  75. sjesc
  76. soupports-colors
  77. spuports-color
  78. srv-configs
  79. suopport-colors
  80. supoprts-color
  81. supporst-color
  82. supports-cloor
  83. supports-colro
  84. supports-coolr
  85. supports-oclor
  86. suppotrs-color
  87. supprots-color
  88. suypport-colors
  89. sypport-color
  90. syupport-colors
  91. tds-publish
  92. tensorflow-estimator-2.0-preview
  93. test-mlw1-bises-celts-borel-sneak
  94. test-mlw1-goals-roker-elmen-bongo
  95. test-mlw1-karat-jowar-scurs-pearl
  96. test-mlw1-noops-semis-edict-bokes
  97. test-mlw1-ogres-bogle-kakas-bogus
  98. test-mlw1-picky-argal-cried-alloy
  99. test-mlw1-piles-perky-glory-sahib
  100. test-mlw1-pling-pangs-birks-cubit
  101. test-mlw1-rakee-clasp-mudir-ovoid
  102. test-mlw1-salto-drags-hunks-chiao
  103. test-mlw1-tasty-fazed-witan-quins
  104. test-mlw2-bises-celts-borel-sneak
  105. test-mlw2-picky-argal-cried-alloy
  106. test-mlw2-pling-pangs-birks-cubit
  107. test-mlw2-salto-drags-hunks-chiao
  108. test-mlw2-tasty-fazed-witan-quins
  109. tlsib
  110. tomcrypt
  111. tsilb
  112. tslbi
  113. uspports-color
  114. utility-common-v2
  115. wanger
  116. warprnnt-pytorch
  117. webcm-dev
  118. websocket-template
  119. Y1zh3e7

These discoveries follow our report last week of over 130 new packages discovered.

Turn on Sonatype Firewall for Automatic Protection

As a DevSecOps organization, we remain committed to identifying and halting attacks, such as those mentioned above, against open source developers and the wider software supply chain.

Users of Sonatype Firewall can rest easy knowing that such malicious packages would automatically be blocked from reaching their development builds.

Sonatype Firewall instances will automatically quarantine any suspicious components detected by our automated malware detection systems, while a researcher is in progress, thereby keeping your software supply chain protected from the start.

Sonatype's world-class security research data, combined with our automated malware detection technology, protects your developers, customers, and software supply chain from infections.

Written by Aaron Linskens
Aaron is a technical writer at Sonatype. He works at a crossroads of technical writing, developer advocacy, and information design. He aims to get developers and non-technical collaborators to work better together in solving problems and building software.