Fake npm Package in Recruiter Repo Designed to Steal Developer Keys and Wallets
A developer received a recruiter message linking to a take-home coding assessment that contained a typosquatted npm package called 'clx-cookieparser', mimicking the legitimate 'cookie-parser' library. The malicious package functioned normally as camouflage while a hidden second-stage dependency — absent from the repo's lockfile — carried the actual payload. That second package was designed to harvest environment variables, API keys, and wallet file paths before exfiltrating them to a remote server. The developer avoided execution by spotting the discrepancy before running any install commands, aided by npm settings that disable automatic install scripts and enforce a 24-hour delay on newly published packages. The incident highlights how supply-chain attacks increasingly target developers' local machines rather than the software they build.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in