
Charlie Eriksen
@CharlieEriksen
Followers
2K
Following
676
Media
88
Statuses
3K
Security Researcher @AikidoSecurity. Founder @weaseljs. Previously @SecCodeWarrior, co-founder at Adversaryio & Principal Security Engineer/Partner @thesyndis
Amsterdam
Joined December 2008
The package reference is quite popular, according to our data from @AikidoSecurity's Threat Intel. Yet somehow it never triggered, I guess?. Why did they change the payload now? Why has the package survived for 8 months? That's very strange.
0
0
2
RT @cyb3rjerry: The phishing domain used in the num2words package compromise is https[://]pypj[.]org/.
0
3
0
RT @SFLinux: @cyb3rjerry @johnk3r @MalwareUtkonos @InvokeReversing I found a weird token in our pypi account, probably the attacker had cre….
0
3
0
RT @cyb3rjerry: A new version (0.5.16) of num2words has been published and is still malicious. Looks like the cleanup was not successful.
0
1
0
RT @cyb3rjerry: This is indeed Scavenger, heads up! Solid catch @johnk3r .Here are the new C2 domains:.- https[://]pokerainteasy[.]su.- htt….
0
2
0
RT @SFLinux: @johnk3r @MalwareUtkonos @cyb3rjerry @InvokeReversing Thanks for the heads up! There was a phishing attack on pypi this mornin….
0
2
0
RT @johnk3r: 🛑 Heads-up: #num2words v0.5.15 (just dropped on PyPI) may be #compromised. Early signs probably link it to #Scavenger, the sa….
0
18
0
For reference, the malicious packages by `panya` happened 12 days ago. And npm only took action today. @AikidoSecurity Intel detected the three malicious packages and automatically flagged them as malware within 5 minutes of their publication. 👏👏.
0
1
4
RT @AikidoSecurity: Introducing Aikido SafeChain 🔒⛓️. SafeChain wraps every npm, yarn, pnpm, and npx install. It blocks malware in real tim….
0
4
0
RT @MalwareUtkonos: @CharlieEriksen There are more than that. Here are all the DLLs that I have found so far
0
3
0
RT @MalwareUtkonos: @Ax_Sharma got-fetch also contains a malicious DLL of the same malware family called "crashreporter.dll".30295311d62893….
0
4
0
It is also significant to note that this is one of the best-documented cases of a targeted phishing attack against an important maintainer in the npm ecosystem. The domain was registered 5 days ago. Lots of lessons to be learned from this across the whole ecosystem.
🚨 5 popular NPM packages totalling over 95m weekly downloads were compromised with malware due to a stolen NPM token. eslint-config-prettier .-- Versions: 8.10.1 - 9.1.1 - 10.1.6 - 10.1.7|. eslint-plugin-prettier.-- Versions: 4.2.2 - 4.2.3. synckit - .-- Version 0.11.9.
1
0
5