Malicious NPM packages target PayPal users
恶意NPM包被用于窃取PayPal用户凭证并劫持加密货币转账。攻击者通过上传带有“PayPal”关键词的恶意包(如oauth2-paypal),诱骗开发者安装以窃取敏感信息。这些包利用预安装钩子运行隐藏脚本,收集并发送数据至攻击者服务器。研究人员建议开发者警惕假PayPal相关包,并采取安全措施防范此类攻击。 2025-4-14 14:8:19 Author: securityaffairs.com(查看原文) 阅读量:6 收藏

Malicious NPM packages target PayPal users

Threat actors deploy malicious NPM packages to steal PayPal credentials and hijack cryptocurrency transfers.

Fortinet researchers discovered multiple malicious NPM packages that are used to target PayPal users. The packages were uploaded to the repository in early March by a threat actor known as tommyboy_h1 and tommyboy_h2, and were used to steal PayPal credentials and hijack cryptocurrency transfers.

“Using PayPal-related names helps these malicious packages avoid detection, making it easier for attackers to steal sensitive information. By including “PayPal” in the name of the malicious packages, such as oauth2-paypal and buttonfactoryserv-paypal, the attackers also create a false sense of legitimacy, tricking developers into installing them.” reads the analysis published by Fortinet. “The code collects and exfiltrates system data, such as usernames and directory paths, which can then be used to target PayPal accounts or be sold for fraudulent purposes.”

Malicious NPM packages use a preinstall hook to run hidden scripts, steal system info, obfuscate data, and exfiltrate it to attacker-controlled servers for future attacks.

Fortinet researchers recommend watching for fake PayPal-related packages, checking network logs for odd connections, removing threats, updating credentials, and staying cautious when installing packages.

The same attacker likely created the tommyboy_h1 and tommyboy_h2 malicious packages to target PayPal users.

“The authors of tommyboy_h1 and tommyboy_h2 are likely the same person, publishing multiple malicious packages in a short time. We suspect that the same author created these packages to target PayPal users.” concludes the report. “We urge the public to be cautious when downloading packages and to ensure they are from trusted sources to avoid falling victim to such attacks.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, malicious NPM packages)




文章来源: https://securityaffairs.com/176530/security/malicious-npm-packages-to-steal-paypal-credentials.html
如有侵权请联系:admin#unsafe.sh