NEWS 38 packages pretended to be Apple and Google tools. The attack on developers almost ended with a large-scale compromise

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,507
The bet was made on the trust of habitual addictions and an error that is easy to ignore.
1778575872472.png
Security specialists revealed a large malicious campaign against developers, in which the attacker relied not on hacking ready-made products, but on the weaknesses of assembly processes. Through the public register of NPM, he tried to slip malicious bags under the guise of internal tools of large companies, hoping that automatic development systems themselves would load the fake.

According to Panther Threat Research, in the period from 24 to 30 April 2026, 38 malicious packages appeared in NPM. They are associated with an Indonesian attacker who used the pseudonym “frank” and the main account frengki07077. Accounts raya4321, ftol and frengki4321 were also used for publication.

The main technique was Dependency Confusion (tasting tolerance). The author of the attack selected names with a fragment “internal” to make the packages look like the closed libraries of Apple, Google, GCP, Alibaba and Aliyun. With an erroneous setting of the CI/CD, the public package could get priority over this internal dependence and be met during a normal installation.

The largest group simulated Apple’s tools, including App Store libraries, PKI, CloudKit utilities, and infrastructure components. In the names there were words indicating bypassing the defenses, secrecy and data leakage. Individual versions like v3, v9 and v99 had to give packets the appearance of conventional dependencies in packages.

Packages targeting Google and GCP were disguised as assembly, logging, monorepository and audit utilities. Their task was to collect the service keys of GCP, OAuth-tokens and Kubernetes configurations. In the Alibaba cluster, the attacker imitated the internal components of Alibaba Cloud SDK and was looking for Aliyun RAM keys. The frank-newton3 series was closer to the universal toolkit for .env-fid files, DB_ variables, SSH keys and MySQL or Postgres dumps.

The malware code was launched through post-startall scenarios after the standard NPm install command. First, the packages collected information about the system, including the username, host and OS data, then looked for secrets and transferred what was found to the control infrastructure. Of particular interest was NPM_TOKEN and NODE_AUTH_TOKEN, since the theft of such tokens could allow the introduction of malicious code into legitimate packages.

Panther links the campaign with one operator on a repeated pseudonym frank, similar account names, Indonesian comments in code and shared webhook addresses in individual packets. The rotation of accounts, according to the company, helped to keep part of the infrastructure after the removal of individual publications.

Development teams are advised to check circulate to public NPM packets with “internal” in the name, control post-standard scenarios in CI/CD and track the access of assembly processes to ~/.npmrc, ~/.aws/credentials and ~/.kube/config.
 
6,241Threads
82,360Messages
5,987Members
agentLatest member
Top Bottom