CSA at ReversingLabs LLC. Designs file analysis platforms, engines and reverse engineering tools for fun. Something about unpacking and PE file format.
🚨Versions 2.6.2 and 2.6.3 of the PyPI package "lightning" are compromised. RL research note: It is the same type of #Shaihulud malware as in recent Bitwarden and SAP compromises.
It looks like #TeamPCP has again compromised @Checkmarx#VSCode extensions and @Docker images. Newly published VSCode extensions checkmarx.cx-dev-assist (1.17.0 & 1.19.0) and checkmarx.ast-results (2.63.0 & 2.66.0) contain malicious code.
🚨 RL Research Alert!
Look out for the compromised versions 1.14.1 and 0.30.4 of axios npm package with almost 11 billion downloads.
https://t.co/ilS0dR9Jcl
👁️ Be on the look out for compromised versions 1.82.7 and 1.82.8 of the "litellm" PyPI package, which has more than 479 million downloads 🧵👇
https://t.co/Fu70kZ8Koz
🚨 RL researchers occasionally come across interesting techniques used by malware in the wild. One such campaign consisting of 10 packages uses @github gists as a host for the second-stage payload.
https://t.co/lIaAaTfUKo
⚠️ RL #ThreatResearch: A new branch of a fake job recruitment campaign by the NK Lazarus Group, dubbed "graphalgo," is targeting #Javascript & #Python devs with a remote access trojan (RAT). 👇 https://t.co/sQtVRW0D2I
⚠️🧵RL researchers have discovered a malicious #VSCode extension with over 12K installs that has been dormant since December, but now ships a malicious version:
https://t.co/Q3YxmkwCZx
@ReversingLabs This new worm variant includes wiper functionality. Shai-hulud permanently destroy all data in the user's home directory making it unrecoverable. It overwrites the free space where the deleted files used to be. Ensuring that data recovery software cannot restore the files.
RL automated threat detection systems are detecting the new wave of Shai-Hulud npm packages. Look out for the TH15502 policy violation in our Spectra Assure Community. Here is an example of a compromised package: https://t.co/uitFAHk3e5 - More info to follow from @ReversingLabs
@ReversingLabs Just like with the first wave, automated dependency management tools (like DependaBot) are creating pull requests that are helping the worm spread.
After detecting & mitigating multiple supply chain attacks targeting #OSS the past few weeks, RL co-founder & CSA @ap0x had a gut reaction: "Something has to change, because we can’t keep doing this every week." #npm#GitHub https://t.co/f87oJtpvWa
⚠️ RL researchers have found another package compromised on day 3 of the ongoing #npm#phishing campaign. It hides the obfuscated payload in the middle of an already large index.js file.👇 https://t.co/b5LWZ0DxFf