A hacker has compromised a little-known, but popular 2.4MB software package that's downloaded over 100 million times per week and is widely used across apps. The IT security community is sounding the alarm about the attack on Axios, an “npm package” that functions as pre-built software that a developer can easily incorporate into a JavaScript project, and basically lets an app talk to the internet and fetch data. However, a hacker hijacked the account of Axios' lead developer and quietly introduced two malicious software versions on Monday night, according to cybersecurity vendor StepSecurity. To evade detection, the hacker-created versions don't contain any malicious code. Instead, they use an instruction to pull from another software project, called “plain-crypto-js,” which can install malware on the computer. The threat is designed to deliver a macOS, Windows, or Linux-based remote access Trojan, depending on the computer’s operating system, allowing the hacker to rifle through a PC, hijack functions, and potentially steal data. This Tweet is currently unavailable. It might be loading or has been removed. The malware versions are also designed to delete themselves after execution. The good news is that the attack only circulated for about three hours before the malicious plain-crypto-js component was taken down, according to Endor Labs. Still, the attack may have affected numerous software developers considering Axios’s reach. “If you installed either compromised version, treat the system as fully compromised,” Endor Labs says. The security community is calling the incident a “supply chain attack” because any software project that incorporated Axios could have ended up running the attack if it had been configured to run the latest version of the npm package. Cybersecurity vendor Wiz noted the attack was observed in about 3% of the affected environments, including cloud and coding platforms. Another provider called Huntress also observed its
Hacker Tries to Spread Malware to Millions by Hitting 'Axios NPM' Software | PCMag
Read the original article
pcmag.com →