malicious-code-digest-january

Malicious Code Digest Monthly Recap: January

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly Edition)! As we step into this fresh new year, our security researchers have uncovered a staggering 800 malicious packages infiltrating open-source software registries. This discovery sets the tone for 2024, reinforcing the urgent need for vigilant software supply chain security.

Over the past few weeks, our teams have been hard at work identifying and blocking emerging threats to safeguard the integrity of our customers’ software ecosystems. These findings highlight the persistent vulnerabilities within open-source component registries and emphasize the necessity of proactive detection and mitigation strategies.

In January 2024, we analyzed and reported over 400 malicious packages spreading across multiple registries, marking a significant increase compared to previous months. The threats identified range from data exfiltration and typosquatting to dependency confusion attacks, underscoring the evolving tactics used by threat actors.

Week 4: Over 90 Packages Discovered

Key Findings:

  • NPM Packages:
    • autogen_studio:1.0.0
    • sparo-real-repo-test:1.0.0
    • pnpm-sync-api-tests:1.0.0
    • pnpm-sync-api-tests:0.2.0
    • dummy-loosesight-gc:1.11.4
    • sample_cluster:2.9.9
    • browser-data-collector:1.0.0
    • explat-client-react-helpers:1.0.0
    • explat-client:1.0.0
    • calypso-polyfills:1.0.0
    • calypso-stripe:1.0.0
    • eslint-plugin-wpvip:1.0.0
    • happychat-connection:1.0.0
    • herostereo:1.0.1
    • herostereo:1.0.2
    • herostereo:1.0.3
    • calypso-storybook:2.0.0
    • calypso-products:2.0.0
    • calypso-polyfills:2.0.0
    • happychat-connection:2.0.0
    • explat-client-react-helpers:2.0.0
    • explat-client:2.0.0
    • pascoresend:3.2.9
    • theice:6.0.2
    • sandstorm-widgets-nyse-website:7.0.2
    • diffuse-the-rest:1.1.4
    • zkpay-plonky2-contract:1.0.0
    • dex-api-library:1.0.0
    • cosmwasmjs-demo:1.0.0
    • wasmer-term:0.1.0
    • kvpair_db_upgrade:1.0.0
    • zkpay-plonky2-contract:1.0.1
    • pistache-io:1.0.0
    • kuvvet_poc:1.0.1
    • kuvvet_poc:1.0.2
    • kuvvet_poc:1.0.3
    • kuvvet_poc:1.0.4
    • nodejs-paypal-checkout-demo:100.0.0
    • kuvvet_poc:1.0.5
    • gatsby-theme-tinker-tailor:1.1.0
    • home-assignment:9.9.9
    • page-pattern-modal:1.0.0
    • sdk-coin-celo:1.0.0
    • abstract-utxo:1.0.0
    • sdk-coin-btg:1.0.0
    • abstract-eth:1.0.0
    • wpcom-checkout:1.0.0
    • pattern-picker:1.0.0
    • digitalexp-microfrontends-framework:11.1.1
    • sdk-coin-cspr:1.0.0
    • digitalexp-components:10.0.0
    • collapsible-group:1.0.2
    • zkwasm-poc:0.2.0
    • collapsible-group:1.0.3
    • cosmy-wasmy:2.2.3
    • plonkscript-docs:0.0.2
    • plonkscript-ui-project:0.0.2
    • plonkscript-vscode:0.0.2
    • digitalexp-components:11.0.0
    • digitalexp-components:12.1.0
    • digitalexp-components:12.2.0
    • digitalexp-components:12.3.1
    • digitalexp-components:12.4.1
    • digitalexp-components:12.5.1
    • digitalexp-components:12.6.2
    • digitalexp-components:12.7.2
    • digitalexp-components:12.7.7
    • digitalexp-components:13.0.0
    • digitalexp-components:13.0.1
    • digitalexp-components:13.1.1
    • nodejs-paypal-checkout-demo:100.1.0
    • digitalexp-datasource-definitions:9.0.0
    • digitalexp-components:13.1.2
    • digitalexp-datasource-definitions:9.0.1
    • launchdarkly-cpp-server:4.0.0
    • digitalexp-datasource-definitions:9.0.4
    • example-app-node:1.0.0
    • digitalexp-datasource-definitions:9.0.6
    • digitalexp-components:13.1.9
    • magic-enum:9.9.9
    • magic-enum:12.9.9
    • magic-enum:13.9.9
    • sdk-coin-etc:1.0.0
    • sdk-coin-eth:1.0.0
    • sdk-coin-eos:1.0.0
    • sdk-coin-dot:1.0.0
    • sdk-coin-ethw:1.0.0
    • sdk-coin-polygon:1.0.0
    • sdk-coin-eth2:1.0.0
    • sdk-coin-near:1.0.0
    • sdk-coin-ltc:1.0.0
    • sdk-coin-dot:2.0.0
    • sdk-coin-etc:2.0.0
    • sdk-coin-eos:2.0.0

Week 3: Over 46 Packages Discovered

Key Findings:

  • NPM Packages:
    • malware-testbed:1.0.1
    • bigcommerce-cornerstone:6.16.4
    • base-encryption:9.9.10
    • lead-marketing-metadata:99.99.99
    • slack-azure-notifier:1.0.0
    • vuepress-plugin-test-analytics:4.0.3
    • vuepress-plugin-lego-analytics:4.0.2
    • growthbook-app:9.9.9
    • etsy.github.io:9.9.9
    • apple.github.io:9.9.9
    • mathworks.github.io:9.9.9
    • built-with-workers:99.99.99
    • wallet-history-demo-backend:1.1.0
    • bigcommerce.github.io:9.9.9
    • casier:4.9.9
    • nw.gui:1.0.1
    • twilio.github.io:9.9.9
    • dojo_2:1.0.3
    • afip-example-api:1.0.0
    • nebulagl-h3-hexagon-editing:1.0.2
    • dell.github.io:9.9.12
    • ccl-styles-2016:1.8.2
    • collapsible-group:1.0.0
    • collapsible-group:1.0.1
    • roro1:1.0.0
    • codat:9.9.9
    • securedrop:9.9.9
    • crash-handler:6.1.7
    • expect-bundle:6.3.2
    • game_overlay:8.5.8
    • node-window-rendering:9.3.2
    • old-react-chat:7.3.2
    • test-utils-bundle:5.3.7
    • utils-bundle:8.1.6
    • zip-bundle:7.3.1
    • casier:5.9.9
    • casier:6.9.9
    • awsume:9.9.9
    • casier:7.0.0
    • casier:7.2.2
    • pascoresend:3.2.5
    • ibm.github.io:9.9.9
    • swift-login-api:9.9.9
    • skulldentist:1.0.1
  • PyPi Packages

    • markitanalysis:0.0.1
    • getpublicip:1.0.1

Week 2: Over 170 Packages Discovered

Key Findings:

  • NPM Packages:
    • vuepress-plugin-lego-analytics:3.0.3
    • lib-wallet:1.0.0
    • eslint-plugin-paste-internal:9.9.10
    • lambda-sns-dynatrace-sdk:1.1.0
    • dynatrace_config_manager:1.0.0
    • legacy_vis_analyzer:1.1.0
    • geotab-sdk:9.9.10
    • cyclotron-svc:1.0.0
    • mlb-site-core:1.0.5
    • testidneel-test-package:0.0.19
    • snapon-imageviewer-lw:99.9.9
    • ai-plugin-template:1.0.0
    • tokenization-lab:1.1.0
    • codeql-query:1.0.0
    • emergency-pull-request-probot-app:1.1.0
    • vuepress-plugin-lego-analytics:3.0.5
    • vuepress-plugin-lego-analytics:4.0.0
    • grabathon-5.0:1.1.0
    • sg_personal_ui:100.0.1
    • pulumi-automation-sdk-ssh-tunnel:9.9.9
    • resources.data.gov:1.1.0
    • calypso-analytics:999.999.999
    • calypso-apps-builder:999.999.999
    • calypso-babel-config:999.999.999
    • calypso-build:999.999.999
    • calypso-color-schemes:999.999.999
    • calypso-doctor:999.999.999
    • calypso-config:999.999.999
    • calypso-e2e:999.999.999
    • calypso-eslint-overrides:999.999.999
    • calypso-jest:999.999.999
    • fabric-shim-docs:1.0.0
    • interview-code-challenge-full-stack:1.0.0
    • bootcamp-hackathon:1.0.0
    • launchpad-ui:1.0.0
    • css-blocks-ember:1.0.0
    • mapbox-demo-components:1.1.0
    • woocommerce-gateway-plisio:2.0.4
    • paytm-blink-checkout-vue3-example:99.99.99
    • deferred-example:99.99.99
    • paytm-blink-checkout-vue2-example:99.99.99
    • ctmjobs:1.0.0
    • metamask-sdk-e2e:1.0.0
    • leafygreen-ui:1.0.0
    • aem-spa-page-model-manager:9999.999.999
    • aem-spa-component-mapping:9999.999.999
    • lit-mobx:9999.999.999
    • autocomplete-theme-classic:9999.999.999
    • eslint-config-atlassian-fecq:9999.999.999
    • babel-plugin-i18n-calypso:9999.999.999
    • lit-mobx:9999991.999.999
    • lit-mobx:9999999.999.999
    • aem-angular-editable-components:99999999.999.999
    • lit-mobx:999999999.999.999
    • aem-spa-component-mapping:999999999.999.999
    • eslint-config-atlassian-fecq:999999999.999.999
    • lit-mobx:999999999.9999.999
    • aem-react-editable-components:999999999.9999.999
    • babel-plugin-i18n-calypso:9999999999.9999.999
    • aem-spa-component-mapping:9999999999.9999.999
    • aem-angular-editable-components:9999999999.9999.999
    • aem-spa-page-model-manager:999999999.9999.999
    • @mp-food/restaurant-orders:2.0.0
    • @mp-food/knapsack:1.0.0
    • actiris:1.0.0
    • ing-feat-inbox:1.0.1
    • experimenter-docs:9.0.0
    • calling-integration-sdk-demo-react-ts:1.1.0
    • otelcollector:1.0.0
    • babel-plugin-i18n-calypso:10000000001.0.0
    • calypso-analytics:1000.0.0
    • calypso-jest:1000.0.0
    • calypso-build:1000.0.0
    • calypso-eslint-overrides:1000.0.0
    • calypso-color-schemes:1000.0.0
    • controlplane:1.0.0
    • babel-plugin-i18n-calypso:10000000002.0.0
    • eslint-config-atlassian-fecq:1000000003.0.0
    • ui-components-shared:10000000003.0.0
    • ui-components-highlight-vdom:10000000003.0.0
    • autocomplete-theme-classic:10000000003.0.0
    • babel-plugin-i18n-calypso:10000000003.0.0
    • ui-components-highlight-vdom:10000000004.0.0
    • eslint-config-atlassian-fecq:1000000004.0.0
    • ui-components-shared:10000000004.0.0
    • autocomplete-theme-classic:10000000004.0.0
    • calypso-doctor:1001.0.0
    • calypso-config:1001.0.0
    • calypso-color-schemes:1001.0.0
    • calypso-build:1001.0.0
    • calypso-apps-builder:1001.0.0
    • calypso-babel-config:1001.0.0
    • calypso-e2e:1001.0.0
    • calypso-analytics:1001.0.0
    • calypso-jest:1001.0.0
    • calypso-eslint-overrides:1001.0.0
    • autocomplete-theme-classic:10000000005.0.0
    • ui-components-highlight-vdom:10000000005.0.0
    • lit-mobx:1000000005.0.0
    • aem-spa-page-model-manager:1000000006.0.0
    • ui-components-shared:10000000005.0.0
    • aem-spa-component-mapping:10000000006.0.0
    • babel-plugin-i18n-calypso:10000000004.0.0
    • eslint-config-atlassian-fecq:1000000005.0.0
    • calypso-analytics:1002.0.0
    • calypso-apps-builder:1002.0.0
    • calypso-babel-config:1002.0.0
    • calypso-build:1002.0.0
    • calypso-doctor:1002.0.0
    • lit-mobx:1000000006.0.0
    • autocomplete-theme-classic:10000000006.0.0
    • aem-spa-component-mapping:10000000007.0.0
    • aem-react-editable-components:1000000008.0.0
    • aem-angular-editable-components:10000000008.0.0
    • ui-components-shared:10000000006.0.0
    • eslint-config-atlassian-fecq:1000000006.0.0
    • babel-plugin-i18n-calypso:10000000005.0.0
    • ui-components-highlight-vdom:10000000006.0.0
    • calypso-jest:1003.0.0
    • calypso-eslint-overrides:1003.0.0
    • calypso-doctor:1003.0.0
    • calypso-e2e:1003.0.0
    • calypso-build:1003.0.0
    • calypso-typescript-config:1.0.0

Week 1: Over 150 Packages Discovered

Key Findings:

  • NPM Packages:
    • glia-widgets-ionic:1.2.1
    • glia-widgets-ionic:1.2.3
    • payouts-banking-info:5.0.0
    • eslint-v7:9.9.9
    • cbpay-js:3.0.0
    • treedome:1.0.0
    • smaato-shared-ui-audience-targeting:9.9.9
    • nativescript-gainsight-px2:1.11.2
    • zqdl333:99.9.9
    • zqdl555:55.5.5
    • zqdl111:11.1.1
    • zqdl222:22.2.2
    • console-webapp-static-server:1.0.0
    • issue-label-notification-action:1.1.0
    • lambda-demo:1.1.0
    • webinarwebhookapp:1.1.0
    • platform-browser-dynamic:13.2.1
    • eslint-config-smaato:9.9.9
    • platform-browser-dynamic:13.2.2
    • air-dao:1.0.0
    • flow-for-vscode:3.0.1
    • ai-playground:3.0.0
    • firefox-ios:1.1.0
    • nimiq-validators-trustscore:1.0.0
    • nimiq-pool:1.0.1
    • nimiq-albatross-policy:1.0.0
    • core-example:1.0.1
    • imports_exports:1.1.2
    • player-workshop:1.1.0
    • @whoever_momo/my-first-npm-module:1.0.5
    • api-demo-sample-lib4:1.0.1
    • tinywallet:4.0.0
    • xapi_test:1.1.0
    • @g.genie/api-demo-sample-lib4:0.3.0
    • testing-in-reise:5.2.0
    • frontend-testing-redefined:4.0.0
    • braze-web-sdk:3.0.0
    • circuit-breaking:3.9.0
    • circuit-breaking:3.9.1
    • lit-2:4.0.0
    • chrome-api-utils:1.1.0
    • lit-3:3.2.2
    • parliament-ui-components:6.1.1
    • pkl-vscode:9.9.15
    • tree-sitter-pkl:9.9.0
    • gbc-viewer:1.0.0
    • tree-sitter-pkl:9.9.1
    • markets-history-data:1.0.0
    • podium-pride:1.0.0
    • jazz_token-authorizer:1.1.0
    • tt4b:1.1.0
    • tt4b:1.1.1
    • electron-builder-13:13.3.4
    • emoji-datasource-google-blob:3.1.2
    • typescript-react-redux-boilerplate:1.1.0
    • selectkit1:9.9.9
    • hd-base:99.0.2
    • uber-direct-js-sdk-examples:1.1.0
    • tree-sitter-strings:1.0.0
    • @vf-org/smapi-js-core:8.2.0
    • zetessf:1.0.0
    • @sanchezcoding/fetchs:1.1.8
    • parliament-ui-components:7.1.1
    • gbc-viewer:1.1.0
    • tree-sitter-pkl:9.9.2
    • ecpfs-react-jest-helpers:2.0.0
    • electron-wix-msi-local:4.0.0
    • wundergraph-cosmo:1.0.0
    • jpl-branding:2.0.4
    • jpl-branding:2.0.5
    • jpl-branding:2.0.7
    • hts-open-dex-react-ui:1.0.0
    • 3cx-call-control-apps:1.0.0
    • mozilla-addons-frontend:1.0.0
    • jpl-branding:2.0.8
    • pre-commit-tasks:1.0.0
    • bridge-transaction-parser:1.2.3
    • addons-pm:3.0.0
    • digitalexp-lowcode-runner-app:10.0.0
    • jpl-branding:2.0.10
    • yandex-music-int:1.0.0
    • @bughunter_99/webpack-demo-2:9.9.9
    • sendbird-moderation-dashboard:2.2.2
    • jpl-branding:2.1.0
    • grafana-sentry-datasource:1.0.3
    • dbx-js-tools:1.2.3
    • dbx-js-tools:3.2.3
    • operaextensions.js:9.9.9
    • shopify-ecommerce-shopping-cart:9.9.9
    • grafana-sentry-datasource:1.0.4
    • jpl-branding:2.1.1
    • passkeys-resources-website:1.0.0
    • gatsby-hampton-theme:1.0.0
    • alchemy-web3-webpack-example:1.1.0
    • angular-blockchain-wallet:1.0.0
    • adblock-resources:1.1.0
    • electron-builder-13:13.12.5
    • okta-help:101.0.9
    • wc-skroutz-analytics:9.9.9
    • octuple:4.4.4
    • qa-octuple:2.5.6
    • storytel.github.io:9.9.9
    • groots645-npm-package:1.4.4
    • opensea-developer-docs:9.9.9
    • op-vscode:1.1.0
    • 1password-sdk-exapmles:1.0.0
    • packs-starter:1.1.0
    • automerge-action:9.9.9
    • slack-opsgenie-alert-creator:9.9.9
    • plib-ai-chat-response:9.9.9
    • mapsapi-polylabeler:2.0.0
    • parseq-tracevis:5.0.0
    • contrast-local-scan-action:9.9.9
    • parseq-tracevis:1.0.0
    • react-redux-v8:9.9.9
    • bitdefender-sitemap-creator:9.9.9
    • geotab-sdk:9.9.9
    • romanes-eunt-domus-jd-1337:1.0.1
    • romanes-eunt-domus-jd-1337:1.0.6
    • romanes-eunt-domus-jd-1337:1.0.7
    • romanes-eunt-domus-jd-1337:1.0.9
    • romanes-eunt-domus-jd-1337:1.0.12
    • vscode-gestalt:1.0.0
    • tile-service-openlayer:2.2.0
    • tile-service-openlayer:2.3.0
    • tile-service-openlayer:2.4.0
    • tile-service-openlayer:3.0.0
    • tile-service-openlayer:3.1.0
    • prombox:9.9.9
    • zapier-platform-boilerplate:9.9.9
    • ie8-dom-define:1.0.0
    • is-array-iter:1.0.0
    • testidneel-test-package:0.0.10
    • testidneel-test-package:0.0.13
    • equipment-icon-mapper:9.9.9
    • bigcommerce-cornerstone:6.16.2
    • gnosis-twitter-bot:1.1.0
    • build-stuff:1.0.0
    • text-unicode-webpack:1.0.0
    • mlb-site-core:1.0.1
    • mlb-site-core:1.0.2
    • mlb-site-core:1.0.3
  • PyPi Packages
    • tiktalk:0.1.1

Secure Your Open Source Dependencies against Vulnerabilities and Malicious Code

Minimize risks and protect your applications from malicious packages with Xygeni Early Malware Detection. Prioritize and address the vulnerabilities that matter most. Our comprehensive solution offers real-time monitoring of your dependencies to detect and mitigate threats before they impact your software.

Managing open-source components in the current software development landscape is crucial due to the rising vulnerabilities and malicious code threats. Xygeni’s Open Source Security solution scans and blocks harmful packages upon publication, dramatically minimizing the risk of malware and vulnerabilities infiltrating your systems. Our comprehensive monitoring spans multiple public registries, ensuring all dependencies are scrutinized for safety and integrity. Xygeni enhances your team’s ability to maintain secure and reliable software projects by contextually prioritizing critical issues and facilitating streamlined remediation processes.

sca-tools-software-composition-analysis-tools
Prioritize, remediate, and secure your software risks
14-day free trial
No credit card required

Secure your Software Development and Delivery

with Xygeni Product Suite