Supply chain
MUT-8694 npm and PyPI Malicious Package Campaign
Primary Source βIncident Details
Datadog Security Labs identified a coordinated supply chain attack campaign (tracked as MUT-8694) active from at least October 10, 2024, targeting both the npm and PyPI package ecosystems β the first observed simultaneous campaign across both registries by a single threat actor. The campaign used 42 malicious PyPI packages and 18 npm packages, most typosquatting legitimate names. Packages predominantly targeted Roblox developers (stealing Roblox cookies, browser passwords, crypto wallets, Telegram sessions). Malware payloads included Blank Grabber and Skuld Stealer (open source infostealers). Targeted Windows users. The campaign highlighted the risk of cross-ecosystem coordinated supply chain attacks by a single threat actor.
Technical Details
- Initial Attack Vector
- Typosquatting: malicious packages uploaded to npm and PyPI mimicking legitimate library names to trick developers into installing them
- Vendor / Product
- npm registry; PyPI
- Software Package
larpexodus (PyPI); various typosquatted Roblox-related npm packages (42 PyPI + 18 npm packages total)- Malware Family
- Blank Grabber infostealer; Skuld Stealer
Timeline
- 2024-10-10 Breach occurred
- 2024-10-01 Publicly disclosed