| |
Why Does an NPM Math Library Need an Encrypted Loader?
Security researchers discovered a malicious remote access implant hidden in a counterfeit npm package called mathmain that impersonates the popular mathjs library. The malware uses encrypted code that remains dormant until a specific mathematical equation is solved, triggering decryption of a payload that enables attackers to execute arbitrary commands on the infected system via a public chat service and blockchain network. The attack was identified through analysis of obfuscated code that contained suspicious function calls within the solver module that secretly exfiltrated matrix data as an encryption key.
Read Full Article →
← More Tech news