
Typosquatting campaign delivers r77 rootkit via npm
ReversingLabs discovered that one “s” was all that separated a legit npm package from a malicious twin that delivered the r77 rootkit — and was downloaded more than 700 times.

Software Threat Researcher, ReversingLabs. Lucija works on the TitaniumCore Team.
find Lucija Valentić on:

ReversingLabs discovered that one “s” was all that separated a legit npm package from a malicious twin that delivered the r77 rootkit — and was downloaded more than 700 times.

ReversingLabs researchers have identified more than a dozen malicious packages targeting Roblox API users on the npm repository. This latest campaign recalls a 2021 attack.

“Write once, infect everywhere” might be the new cybercrime motto, with newly discovered campaigns showing malicious npm packages powering phishing kits and supply chain attacks.

ReversingLabs researchers discovered two malicious packages that contained TurkoRat, an open source infostealer that lurked on npm for two months before being detected.

What’s in a name? Here's how bad actors are pushing malware on the Python Package Index under the guise of legitimate yet abandoned open source modules.

ReversingLabs researchers discovered dozens of malicious packages on Python Package Index that mimic popular libraries

Aabquerys is a malicious npm package discovered typosquatting on a legitimate module that downloads malicious components
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial