BOOK THIS SPACE FOR AD
ARTICLE AD22. July 2021
This article has been indexed from Softpedia News / Security
A software package available in the official NPM repository turned out to be a front for a program aimed at stealing stored credentials from the Chrome web browser, according to The Hacker News. After being reported yesterday, the malicious package was removed from the repository.
The malicious package is called “nodejs net server” and has been downloaded more than 1,283 times since February 2019. One questionable detail is that the associated repository leads to non-existent locations on GitHub.
While the original version of the package was only released to test the NPM package publishing process, the developer, named Chrunlee, made revisions with the purpose of implementing a remote shell capability. Then a script (“hxxps:/chrunlee.cn/a.exe”) was added to down…