Malicious Code Bombs Target Amazon, Lyft, Slack, Zillow
#1
Information 
Quote:Researchers have spotted malicious packages targeting internal applications for Amazon, Lyft, Slack and Zillow (among others) inside the npm public code repository — all of which exfiltrate sensitive information.

The packages weaponize a proof-of-concept (PoC) code dependency-confusion exploit that was recently devised by security researcher Alex Birsan to inject rogue code into developer projects.
 
Internal developer projects typically use standard, trusted code dependencies that are housed in private repositories. Birsan decided to see what would happen if he created “copycat” packages to be housed instead in public repositories like npm, with the same names as the private legitimate code dependencies.

“Is it possible that some of PayPal’s internal projects will start defaulting to the new public packages instead of the private ones?” he asked. And the answer was yes.

In Birsan’s case, he tested this “dependency confusion” using benign PoC code blocks. These were uploaded to public repositories – and he simply sat back and waited to see if they would be imported. His hunch proved correct, demonstrating how outside code can be imported and propagated through a targeted company’s internal applications and systems, with relative ease — including at Apple, Microsoft, Netflix, PayPal, Shopify, Tesla and Uber.

Read more: https://threatpost.com/malicious-code-bo...ow/164455/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.6.5 Added edit...Kool — 12:03
Microsoft Edge Moves to Two-Week Release...
Microsoft has anno...harlan4096 — 10:44
Bitdefender 27.0.60.337
Bitdefender 27.0.6...harlan4096 — 07:57
K-Lite Codec Pack 19.7.5 / 19.7.6 Update
Changes in 19.7.6 ...harlan4096 — 07:56
HWMonitor 1.64 for Windows
HWMonitor 1.64 for...harlan4096 — 07:55

[-]
Birthdays
Today's Birthdays
avatar (32)horancos
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
Decimuss's profile Decimuss

>