Sept. 28, 2023, 10:45 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Researchers have discovered a concerning surge in deceptive npm and PyPI packages distributed as part of a malicious campaign, aimed at extracting Kubernetes configurations and SSH keys from compromised systems.


The First Signs of the Campaign


The campaign was first identified on September 12, 2023, and has been ongoing since then.


Initially, a total of 14 malicious npm packages were identified as part of this campaign, published from different npm accounts:



  • @am-fe/hooks

  • @am-fe/provider

  • @am-fe/request

  • @am-fe/utils

  • @am-fe/watermark

  • @am-fe/watermark-core

  • @dynamic-form-components/mui

  • @dynamic-form-components/shineout …

campaign compromised distributed keys kubernetes malicious malicious npm npm packages pypi pypi packages researchers september ssh ssh keys systems

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Cloud Security Analyst

@ Cloud Peritus | Bengaluru, India

Cyber Program Manager - CISO- United States – Remote

@ Stanley Black & Decker | Towson MD USA - 701 E Joppa Rd Bg 700

Network Security Engineer (AEGIS)

@ Peraton | Virginia Beach, VA, United States

SC2022-002065 Cyber Security Incident Responder (NS) - MON 13 May

@ EMW, Inc. | Mons, Wallonia, Belgium

Information Systems Security Engineer

@ Booz Allen Hamilton | USA, GA, Warner Robins (300 Park Pl Dr)