UNCOS

Here’s how carefully concealed backdoor in fake AWS files escaped mainstream notice

Here’s how carefully concealed backdoor in fake AWS files escaped mainstream notice

image via Ars Technica

July 15, 2024, 8:18 PM

Two fake AWS packages downloaded hundreds of times from the open source NPM JavaScript repository contained carefully concealed code that backdoored developers' computers when executed. The packages were attempts to appear as aws-s3-object-multipart-copy, a legitimate JavaScript library for copying files using Amazon’s S3 cloud service. The fake files included all the code found in the legitimate library but added an additional JavaScript file named loadformat.js. That file provided what appeared to be benign code and three JPG images that were processed during package installation. One of those images contained code fragments that, when reconstructed, formed code for backdooring the developer device.

Read original article

Entities Mentioned

Ross Bryant

Topics Covered

Biz & ITSecuritybackdoorsopen sourcesteganigraphy

Comments (0)

No comments yet.