Breaking
December 16, 2024

Huge cybercrime attack sees 390,000 WordPress websites hit, details stolen | usagoldmines.com


  • Researchers found a malicious package on NPM, uploaded a year ago
  • It was benign at first, and introduced malware later via an update
  • The malware stole hundreds of thousands of secrets and installed cryptojackers on dozes of computers

For roughly a year, hackers have been infecting red teamers, penetration testers, security researchers, as well as other hackers, with a piece of malware that steals WordPress credentials and other sensitive data, and installs cryptominers on compromised endpoints.

As a result, login credentials for some 390,000 WordPress accounts were stolen, and dozens of systems were found mining Monero.

Cybersecurity researchers Datadog Security Labs spotted the attack on the NPM package repository, and in GitHub, after researchers from Checkmarx also sounded the alarm on the same campaign recently.

The package was pretending to be an XML-RPC implementation, and was first uploaded to the repository in October 2023. Until November 2024, when it was finally discovered as malicious, it received 16 updates.

Legitimate at first

Datadog noted ho the attackers were tactical in their approach, first uploading a package that was legitimate and worked as intended. The malicious code was introduced in later versions, and designed to steal SSH keys, bash history, and other data, every 12 hours. The data it collects would get extracted either via Dropbox, or File.io.

To make matters worse, researchers and security pros that would introduce XML-RPC into their own products would just expand the reach of the malware, turning it into a full-blown supply chain attack.

Datadog said that ultimately, the team found 68 compromised systems that were actively mining the Monero currency. Monero, with the XMR ticker, is most often mined with a cryptojacker called XMRig. This is a popular currency among thieves since it’s fully anonymous and very difficult to trace.

The identity of the threat actors was not discovered, but the researchers dubbed the group MUT-1224, which is short for Mysterious Unattributed Threat.

Major code repositories remain a vital platform for cybercriminals, the researchers concluded, stressing that developers should be extra careful when using open-source software.

Via BleepingComputer

You might also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

This Ryzen 7 mini PC with triple 4K support is only $309 right now | usagoldmines.com
The 10 Best True Crime Podcasts of 2024 Lauren Passell | usagoldmines.com
You Can Get the Amazon Fire TV Stick Lite for Its Lowest Price Ever Right Now Pradershika Sharma | u...
All the Smart Devices That Can Help Make Your Aging Parents’ Lives Easier Amanda Blum | usagoldmines...
Butterfly Lets You Use Bluesky From Your Apple Watch Pranay Parab | usagoldmines.com
The Dreame L40 Ultra Is Better at Vacuuming Than Mopping Amanda Blum | usagoldmines.com
You Can Now Test 'Recall,' Windows’ Controversial AI Feature David Nield | usagoldmines.com
United, Delta, and Air Canada Will Begin Supporting Find My for Lost Luggage This Week Joe Rossignol...
Apple Sports App Updated With Key Plays, Pregame Lineups, and More Eric Slivka | usagoldmines.com
Most iPhone Users Uninterested in Apple Intelligence, Survey Suggests Hartley Charlton | usagoldmine...
Reebok unveils stunning new Nano X5, and it might be the ultimate gym shoe stephen.warwick@futurenet...
The best cheap graphics card prices and deals for December 2024 alex.whitelock@futurenet.com (Alex W...
These are the AI assistants developers are actually using - and how they're using them | usagoldmin...
12 Days of OpenAI – Live updates from Day 8 including ChatGPT, Sora, o1 and more | usagoldmines.com
Don't panic – those mystery drones over New Jersey might not be so mysterious after all lance.ulanof...
Is AI on smartphones just a gimmick? Most iPhone and Samsung owners think so, according to a new pol...
All the Smart Devices That Can Help Make Your Aging Parents’ Lives Easier Amanda Blum | usagoldmines...
Apple Reveals Most Downloaded Apps and Games of 2024 Hartley Charlton | usagoldmines.com
Best Buy Takes $70 Off Every 10th Gen iPad With Christmas Delivery Mitchel Broussard | usagoldmines....
Windows 11’s Start menu recommendations are being improved – but I’m still not impressed, Microsoft ...
I used Grok’s new free tier on X but I can’t show you the results because it could infringe Nintendo...
US government warns water firms to secure infrastructure at risk online | usagoldmines.com
Infosys co-founder once again claims 70-hour work weeks are "necessary" and will create jobs | usag...
The rise of the IT Generalist | usagoldmines.com
Unlocking AI's ROI: How to justify the investment | usagoldmines.com
US set to allow tech giants to control access to AI chips | usagoldmines.com
Silo scores a two-season renewal for the hit Apple TV Plus show and I can’t wait to dig up more myst...
Cl0p ransomware group says it was behind Cleo attacks | usagoldmines.com
Why do we get headaches from drinking red wine? Andrew Waterhouse and Apramita Devi, The Conversatio...
This Windows keyboard shortcut guards your PC from prying eyes | usagoldmines.com
Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com
Apple TV+ Sci-Fi Series 'Silo' Renewed for Third and Fourth Seasons Joe Rossignol | usagoldmines.com
I'm excited for Apple's new nature docuseries The Secret Lives of Animals, and this exclusive clip o...
I never would’ve bought a $700 office chair… until I tried this one | usagoldmines.com
What’s new when shopping for a laptop in 2025? 8 things to keep in mind | usagoldmines.com
Foldable iPad With ~20-Inch Display Likely Set for 2028 Launch Tim Hardwick | usagoldmines.com
Eufy Launches 4K E30 Indoor Camera With HomeKit Support Tim Hardwick | usagoldmines.com
Google Agentspace wants to use AI to help you find out all the work information you need | usagoldm...
New iPhone 17 Air price rumor could tempt buyers away from the Samsung Galaxy S25 Slim | usagoldmin...
I'm tired of having so many streaming subscriptions – here's why I'm switching to Shudder | usagold...
Next-gen TV tech tipped for CES 2025 reveal as HDMI 2.2 gets itself connected | usagoldmines.com
Millennials are indulging in impulse shopping more than ever | usagoldmines.com
The latest Oura and Samsung Galaxy Ring rival has a watch-style display, and I hate it matt.evans@fu...
Google is adding a 'join' feature to its NotebookLM AI podcast generator, so you can become part of ...
RCS encryption is still months away following major US telecomms breach jamie.richards@futurenet.com...
This robot lawn mower turns into a snow blower, and I've never wanted to wake up to a blocked drive ...
It now looks very likely that the Samsung Galaxy S25 will launch on January 22 | usagoldmines.com
It looks like Apple will finally fix the Magic Mouse’s fatal design flaw – but I probably still won'...
Some YouTube TV fans are using a classic trick to escape the price hike hamish.hector@futurenet.com ...
DJI Osmo Action 6 leaks just three months after the launch of the Action 5 Pro | usagoldmines.com
AirTag 2 upgrade could bring significant improvements to Apple’s trackers alexblake.techradar@gmail....
Nvidia RTX 5090 rumor suggests flagship GPU might not guzzle as much power as previously claimed – b...
Thousands of Rhode Island citizens have data stolen after social services hit by cyberattack benedic...
Paramount Plus releases a new action-packed 1923 season 2 trailer and it's the cowboy chaos I needed...
Next-gen TV tech tipped for CES 2025 reveal as HDMI 2.2 gets itself connected | usagoldmines.com
Buying a TV in 2025? Expect lower prices, more ads, and an OS war. Scharon Harding | usagoldmines.co...
All I want for Christmas is the trailer for James Gunn's Superman movie, and it sounds like my wish ...
CD Projekt Red confirms that Ciri has been recast in The Witcher 4 dash.wood@futurenet.com (Dashiell...
It's official: Samsung's The Premiere leads the 8K projector pack by gaining the first ever 8KA cert...
Deepfakes and AI attacks are worker's biggest security worries | usagoldmines.com
Schools are facing greater cybersecurity threats than ever before | usagoldmines.com
Apple's giant foldable iPad could be crease-free and run macOS apps, new report claims alexblake.tec...
Nvidia RTX 5070 Ti could turn up before RTX 5070 – and new rumor suggests it might be the powerhouse...
Best gaming laptops under $1,000: Expert picks that won’t break the bank | usagoldmines.com
iOS 18.2: Bring Volume Slider Back to iPhone Lock Screen Tim Hardwick | usagoldmines.com
The secret to feeling good? Make friends with your fridge | usagoldmines.com
Finally, an AirTag dupe that’s worth the hype | usagoldmines.com
How To Get Shortest Routes Using Dynamics CRM Map Integration With Azure Maps? Devik Gondaliya | usa...
How To View Individual Record in Dynamics 365 CRM and Azure Maps? Devik Gondaliya | usagoldmines.com
This new 3D printing technology could make housing construction faster and more efficient udinmwenef...
NYT Strands today — my hints, answers and spangram for Monday, December 16 (game #288) | usagoldmin...
NYT Connections today — my hints and answers for Monday, December 16 (game #554) | usagoldmines.com
Quordle today – my hints and answers for Monday, December 16 (game #1057) | usagoldmines.com
AirTag 2 Expected to Launch Next Year With 'Considerable' Upgrade to Item Tracking Joe Rossignol | u...
Ransomware defenses are being weakened by outdated backup technology, limited backup data encryption...
AWS, Azure and Google Cloud credentials from old accounts are putting businesses at risk udinmwenefo...
Build your own super mini PC with this $338 AMD AM5 barebone workstation that has OCuLink, two 2.5Gb...
'iPhone 17 Air' With 'Major' Design Changes and 19-Inch MacBook Detailed in New Report Joe Rossignol...
The Samsung Galaxy S25 is tipped to come with a huge Bixby AI upgrade | usagoldmines.com
5 useful PC upgrades to plug into your unused PCIe slots | usagoldmines.com
Best Windows backup software 2024: Protect your data! | usagoldmines.com
Best VPNs for Android 2024: Our picks for phones and tablets | usagoldmines.com
9 tweaks that turn off your Windows PC’s most annoying ads | usagoldmines.com
Apple 'Working' on Redesigned Magic Mouse With a Long-Awaited 'Fix' Joe Rossignol | usagoldmines.com
China launches new compact radiation detection chip for semiconductor self-reliance udinmwenefosa@gm...
We just got a hint that we might have to pay more for the iPhone 17 | usagoldmines.com
Identity fraud attacks using AI are fooling biometric security systems udinmwenefosa@gmail.com (Efos...
This free tool offers SMBs critical insights into compromised credentials found on the dark web udin...
NotLockBit ransomware targets Apple users with advanced file-locking and data exfiltration udinmwene...
Microsoft 365 fees adding up? Get a permanent Office license for cheap | usagoldmines.com
Master the art of AI and make automation your new superpower | usagoldmines.com
AI investment isn't slowing down — venture capitalists are funding startups while trying to grapple ...
NYT Strands today — my hints, answers and spangram for Sunday, December 15 (game #287) | usagoldmin...
Quordle today – my hints and answers for Sunday, December 15 (game #1056) | usagoldmines.com
NYT Connections today — my hints and answers for Sunday, December 15 (game #553) | usagoldmines.com
US border surveillance towers face significant operational failures — vast areas unwatched, national...
Hey sysadmin, this is the perfect Christmas laptop gift for you; HX 370-powered Pocket 4 has a RS232...
Chinese flagship phones are great value for money, but they won't stay cheaper for much longer – her...
Rivian Gets Google Cast, YouTube App in Holiday Update Kellen | usagoldmines.com
The Samsung Galaxy S25 Ultra could come with a stylish new color | usagoldmines.com

Leave a Reply