Embedded malicious HTTP desync probes
Fallout in go, Aug 3 – Aug 9
What we caught this week while monitoring over 163,642,969 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.
SUNDAY
Sun Aug 9 · 21 catches · 0 waves · 3 singlesAuto-executes obfuscated credential stealer
Hostile dependency embedded in sample
Hostile dependency: HTTP desync probe
SATURDAY
Sat Aug 8 · 21 catches · 0 waves · 3 singlesnpm install hook exfiltrates env
hostile dependency impersonation
Hostile dependency: HTTP desync probe
FRIDAY
Fri Aug 7 · 15 catches · 0 waves · 3 singlesHostile dependency class present
Hostile dependency: http_parser.rb
HTTP desync probe in dependency
THURSDAY
Thu Aug 6 · 14 catches · 0 waves · 3 singlesNPM install hook exfiltrates env
Hostile dependency: HTTP desync probe
WEDNESDAY
Wed Aug 5 · 10 catches · 0 waves · 3 singlesObfuscated dropper with evasion techniques
Hostile dependency: credential exfiltration
malicious htmlescape dependency
TUESDAY
Tue Aug 4 · 12 catches · 0 waves · 3 singlesHostile dependency class present
PowerShell dropper in main.go
malicious npm dependency embedded
MONDAY
Mon Aug 3 · 19 catches · 0 waves · 3 singleshostile dependency htmlescape
HTTP desync probes in dependency
Contains WordPress plugin backdoor generator