Malicious Code Digest Monthly Recap: June 2024 Edition

Welcome to the latest edition of the Xygeni Malicious Code Digest (Monthly edition), where our security researchers bring you the latest discoveries of malicious packages in software registries.

This month, our teams have been hard at work identifying and blocking threats to ensure the security of our customers’ software supply chain. Over the past few weeks, we uncovered and reported a significant number of malicious packages infiltrating various open-source component registries. These findings highlight the ongoing vulnerabilities and the critical need for robust security measures.

In June 2024, we confirmed a total of over 60 malicious packages across multiple registries. This includes a range of threats from data exfiltration and typosquatting to dependency confusion attacks. Here’s a detailed breakdown of our findings throughout the month:

Week 4: Over 10 Packages Discovered

  • Key Findings:
    • NPM Packages:
      • world-id-onchain-starter:2.0.0
      • orderly-omnichain-occ:1.0.0
      • openstad-component-forms:1.0.0
      • bootstrap-4-package:0.0.1
      • @wdp-gov/lineage-component:1.0.402
      • @wdp-gov/lineage-component:1.0.401
      • @wdp-gov/lineage-component:1.0.40
      • @wdp-gov/catalog-serialization-engine:3.0.195
      • @wdp-gov/catalog-serialization-engine:2.2.5
      • @daimler-rcms/api-client:1.0.99

Week 3: Over 10 Packages Discovered

  • Key Findings:
    • NPM Packages:
      • wordpress-theme-core:0.0.1
      • tyk-developer-portal:1.0.0
      • storefront-h5-sdk:1.0.0
      • flormar-global:1.0.0
      • ej2-client-node:1.0.0
      • comet-chat-react-ui-kit:1.0.3
      • @wdpx-catalogs/data-asset-previewer:8.0.115
      • @wdpx-catalogs/common-ui-components:5.0.10
      • elitebots-prevnames-discord:1.0.6
    • PyPI Package:
      • nt4PAdyP3:0.0.2
      • importlib-metadate:99.99
      • importlib-metadate:99.9

Week 2: Over 20 Packages Discovered

  • Key Findings:
    • NPM Packages:
      • @jarvis-shell/eslint-config-shell-mfe-base:1.0.1
      • cosma-ui-icons:9999.999.3
      • randombullshitgo-js:105.0.1
      • aws-check:105.0.1
      • aws-logs:100.0.1
      • bootstrap-npm-webpack:1.0.0
      • censhare-web:2021.1.1
      • core-webpack:105.0.1
      • dell-ui-bootstrap:1.3.5
      • djs14-logger:1.1.2
      • exel-js:105.0.1
      • get-hydrated-cms-data:1.0.1
      • masterfresh:0.0.2
      • nppe_ttt_datalayer:1.0.0
      • ozon-js:105.0.1
      • ozonid:105.0.1
      • purina-parent-theme:1.0.0
      • pwnkunwar:1.0.4
      •  rb-payment-wallet:0.1.2
      • rey-frontend-fp:19.19.109
      • rey-vue-common:101.101.102
      • rey-vue-smarttable:101.101.102
      • scm-design-system-cra:0.1.1
      • scm-design-system:0.2.9
      • v2-core:105.0.1
      • virtuoso-ui-common:3.0.0
      • virtuoso-web-chat:1.0.13

Week 1: Over 10 Packages Discovered

  • Key Findings:
    • NPM Packages:
      • ahmedwael00:250.0.0
      • alexablueprintswizard:250.0.0
      • eslint-config-bragi:3.0.3
      • export-gltf:1.0.0
      • nespresso-design-system:99.50.2
      • ogg-lru:1.0.2
      • portfolio-organism-adp-wrapper:1.0.0
      • protonme:1301.1.1
      • requessst:1.0.2
      • seller-journey-ui:5.4.7
      • stablecoin-evm:1.0.0
      • xloportailcfn:3.0.24

