Malicious Code Bombs Target Amazon, Lyft, Slack, Zillow
#1
Information 
Quote:Researchers have spotted malicious packages targeting internal applications for Amazon, Lyft, Slack and Zillow (among others) inside the npm public code repository — all of which exfiltrate sensitive information.

The packages weaponize a proof-of-concept (PoC) code dependency-confusion exploit that was recently devised by security researcher Alex Birsan to inject rogue code into developer projects.
 
Internal developer projects typically use standard, trusted code dependencies that are housed in private repositories. Birsan decided to see what would happen if he created “copycat” packages to be housed instead in public repositories like npm, with the same names as the private legitimate code dependencies.

“Is it possible that some of PayPal’s internal projects will start defaulting to the new public packages instead of the private ones?” he asked. And the answer was yes.

In Birsan’s case, he tested this “dependency confusion” using benign PoC code blocks. These were uploaded to public repositories – and he simply sat back and waited to see if they would be imported. His hunch proved correct, demonstrating how outside code can be imported and propagated through a targeted company’s internal applications and systems, with relative ease — including at Apple, Microsoft, Netflix, PayPal, Shopify, Tesla and Uber.

Read more: https://threatpost.com/malicious-code-bo...ow/164455/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Malicious Code Bombs Target Amazon, Lyft, Slack, Zillow - by silversurfer - 03 March 21, 20:10

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 151.0.1
Mozilla Firefox Br...harlan4096 — 08:57
AnyDesk 9.7.4 for Windows
Version 9.7.4 for ...harlan4096 — 08:55
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 08:52
Brave 1.90.124 (Chromium 148.0.7778.179)
Release v1.90.124 ...harlan4096 — 08:49
Screenpresso 2.2.12
Screenpresso 2.2.1...harlan4096 — 08:42

[-]
Birthdays
Today's Birthdays
avatar (50)Mirzojap
avatar (36)idilysaju
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>