Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign

Attackers abused npm's trusted publishing feature to distribute malware in a GHAPPIER campaign.

Bottom line: Attackers abused npm's trusted publishing feature to distribute malware in a GHAPPIER campaign.

What's happening: CloudSEK linked a compromised npm package, 'npm-uuid', to a GHAPPIER campaign, which used trusted publishing in npm to distribute malware. The npm package had valid trusted-publishing provenance. The malware was designed to steal credentials for 'Google' and 'Microsoft' services.

What to do: Security leaders should monitor npm package updates and ensure their organizations are using the latest npm version, with the CVE-2023-22560 patch, to prevent similar attacks.

Source: Infosecurity Magazine