NPM-Pakete, die sich als Geschwindigkeitstester ausgeben, installieren stattdessen Krypto-Miner

Teilen:

A new set of 16 malicious NPM packages are pretending to be internet speed testers but are, in reality, coinminers that hijack the compromised computer’s resources to mine cryptocurrency for the threat actors.

The packages were uploaded onto NPM, an online repository containing over 2.2 million open-source JavaScript packages shared among software developers to speed up the coding process.

CheckPoint discovered these packages on January 17, 2023, all uploaded to NPM by a user named “trendava.” Following the company’s report, NPM removed them the following day.

The sixteen malicious NPM packages installing cryptocurrency miners are:

  • store
  • speedtesta
  • speedtestbom
  • speedtestfast
  • speedtestgo
  • speedtestgod
  • speedtestis
  • speedtestkas
  • speedtesto
  • speedtestrun
  • speedtestsolo
  • speedtestspa
  • speedtestwow
  • speedtestzo
  • finds
  • we find

Most packages feature a name resembling an internet speed tester, but they are all cryptocurrency miners. Although they share the same objective, CheckPoint’s analysts found that each package employs different coding and methods to accomplish its tasks.

“It is fair to assume these differences represent a trial the attacker did, not knowing in advance which version will be detected by the malicious packages’ hunter tools and therefore trying different ways with which to hide their malicious intent,” comments CheckPoint.

“As part of this effort, we’ve seen the attacker hosting the malicious files on GitLab. In some cases, the malicious packages were interacting directly with the crypto pools, and in some cases, they seem to leverage executables for that need.”

For example, the “speedtestspa” package downloads a helper from GitLab and uses it to connect to the cryptocurrency mining pool, whereas “speedtestkas” includes the malicious helper file in the package.

The “speedtestbom” package goes a step further by attempting to hide the cryptocurrency mining pool address, so instead of hardcoding it, it connects to an external IP to retrieve it.

The fourth example given in CheckPoint’s report is the “speedtesto” package which features code from an actual speed testing utility, offering the promised functionality to the unsuspecting user.

Software developers can minimize the chances of falling victim to those supply chain attacks by carefully reviewing the code in any packages they add to their projects.

Furthermore, it is essential only to trust reputable sources and publishers and validate the names to avoid installing malicious typosquatting packages.

Last week, researchers from Phylum disclosed that they found 451 malicious typosquatting packages on PyPi that installed password-stealing malware.

 

(c) Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:42 am, Juli 11, 2025
Wetter-Symbol 18°C
L: 17° | H: 20°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 81 %
Druck: 1021 mb
Wind: 3 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 31%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 9:15 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 20°°C 0 mm 0% 8 mph 81 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 2 mph 81 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 26°°C 0 mm 0% 2 mph 72 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
26° | 30°°C 0 mm 0% 3 mph 48 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 66 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,523.75
5.98%
Ethereum(ETH)
€2,564.20
8.01%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€2.21
6.64%
Solana(SOL)
€141.50
5.25%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.170681
10.44%
Shiba Inu(SHIB)
€0.000012
9.05%
Pepe(PEPE)
€0.000011
16.99%
Peanut das Eichhörnchen(PNUT)
€0.251967
23.06%
Nach oben scrollen