Massive Malicious Attack on NPM: 50k Packages Flooded with Phishing Links

A sudden surge of thousands of malicious packages was uploaded to the NPM open-source ecosystem from multiple user accounts the last weekend.
Further investigation uncovered a recurring attack method in which cyber attackers utilize spamming techniques to flood the open-source ecosystem with packages that include links to phishing campaigns in their README.md files.
The packages were created using automated processes, with project descriptions and auto-generated names closely resembling one another.
The Attackers referred to retail websites using referral IDs, thus profiting from the referral rewards they earned.

Automated Script
The attackers utilized automated processes to publish over 50,000 packages in NPM and created over 1500 user accounts within a few days. These packages’ descriptions promote links to download an offline e-book file shortened using the URL shortening service tinybit.cc.

The link provided by tinybit.cc redirects users to a counterfeit website hosted under the domain pdflivres[.]com. The site displays details about the supposed e-book file and suggests that a copy is available for download. However, upon clicking the download button, users are redirected to various other phishing websites.

Yiddish Captcha
After clicking on the verification links to download the e-book file, I was referred to another website that challenged me to answer a captcha. The creators of this website used the Yiddish language (a language spoken by Ashkenazi Jews, originating in Central and Eastern Europe)

More Redirects
After answering the captcha challenge, I was referred to yet another website. The barrage of redirects didn’t stop there, as I was taken to another website that bombarded me with a flurry of invasive questions and obnoxious advertisements. It seemed as though every click I made was met with another pop-up or redirect, each one more insistent and aggravating than the last. Despite my attempts to close out of the pages and escape the onslaught, the phishers had ensnared me in a web of convoluted redirections that seemed designed to keep me engaged as long as possible.

Referrals Rewards
Eventually, these phishing sites redirect users to eCommerce sites that include referral IDs. In this scheme, when a victim purchases a site like AliExpress after being referred by the threat actor, the threat actor’s account earns a referral reward such as a coupon or store credit. This emphasizes the financial incentive that drives threat actors to engage in phishing campaigns like this.

Conclusion
Last month we saw a similar attack we suspect was made by the same threat actor (https://medium.com/checkmarx-security/how-npm-packages-were-used-to-spread-phishing-links-3d094afcced3)
The scale of this phishing campaign is significant. The battle against threat actors poisoning our software supply chain ecosystem continues to be challenging, as attackers constantly adapt and surprise the industry with new and unexpected techniques.
By working together, we can stay one step ahead of attackers and keep the ecosystem safe. We believe this kind of collaboration is crucial in the fight against software supply chain attacks, and we will continue working together to help protect the open-source ecosystem.
If you would like access to the original metadata or samples from this phishing campaign, please feel free to send an email to supplychainsecurity@checkmarx.com. Our team will be happy to provide you with the information you need.
Massive Malicious Attack on NPM: 50k Packages Flooded with Phishing Links was originally published in Checkmarx Zero on Medium, where people are continuing the conversation by highlighting and responding to this story.
