As per sources, a huge supply chain attack has hit the JavaScript world after 16 top Gluestack react-native-aria NPM packages were found to have malicious code. The packages, which were downloaded nearly 960,000 times per week, were compromised beginning from June 6. The malware injected is a remote access trojan (RAT), granting attackers the ability to execute shell commands, download files, and modify directories. Aikido Security, a cybersecurity company, detected the attack, describing the obfuscated malicious code as inserted at the end of the source files, thus being difficult to notice at first glance. The attack appears to be ongoing, with fresh malicious versions of the packages being published hours before detection. This attack seems to be a coordinated supply chain attack most likely timed to occur over the weekend when there are fewer maintainers online. The injected trojan is the same as in a recent NPM compromise by the same threat actors, who also attacked packages biatec-avm-gas-station and lfwfinance/sdk recently. The attacker used Windows PATH hijacking techniques to hijack legitimate Python installations and execute malware stealthily. With heavy downloads, this compromise will likely impact thousands of development projects and end-user applications built on Gluestack's UI framework. ? To reduce such risks, developers have to scan their projects as soon as possible for the vulnerable packages and revert to secure versions. Regular package dependency monitoring, integrity checking with tools such as npm audit or Snyk, and the use of software supply chain security platforms are imperative. NPM and maintainers must also improve package vetting, and teams must have stricter CI/CD controls to identify anomalies before deploying vulnerable code.
A large-scale phishing campaign has been identified leveraging RFQ (Request for Quotation) themed emails to distribute credential-stealing malware. Attackers disguise malicious HTM...
Two critical vulnerabilities in Progress ShareFile have been identified that can be chained to achieve pre-authentication remote code execution (RCE). Discovered by watchTowr resea...
The FBI has issued a warning highlighting potential security and privacy risks associated with widely used mobile applications developed by Chinese companies. These applications, a...