{"id":1114462,"date":"2024-01-23T12:32:27","date_gmt":"2024-01-23T14:32:27","guid":{"rendered":"https:\/\/teknomers.com\/fr\/des-packages-npm-malveillants-exfiltrent-des-centaines-de-cles-ssh-de-developpeur-via-github\/"},"modified":"2024-01-23T12:32:32","modified_gmt":"2024-01-23T14:32:32","slug":"des-packages-npm-malveillants-exfiltrent-des-centaines-de-cles-ssh-de-developpeur-via-github","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/des-packages-npm-malveillants-exfiltrent-des-centaines-de-cles-ssh-de-developpeur-via-github\/","title":{"rendered":"Des packages NPM malveillants exfiltrent des centaines de cl\u00e9s SSH de d\u00e9veloppeur via GitHub"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">23 janvier 2024<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">R\u00e9daction<\/span><\/span><span class=\"p-tags\">S\u00e9curit\u00e9 logicielle \/ Cha\u00eene d&#8217;approvisionnement<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/01\/Des-packages-NPM-malveillants-exfiltrent-des-centaines-de-cles-SSH.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><\/a><\/div>\n<p>Il a \u00e9t\u00e9 d\u00e9couvert que deux packages malveillants d\u00e9couverts dans le registre des packages npm exploitaient GitHub pour stocker les cl\u00e9s SSH crypt\u00e9es en Base64 vol\u00e9es sur les syst\u00e8mes de d\u00e9veloppement sur lesquels ils \u00e9taient install\u00e9s.<\/p>\n<p>Les modules nomm\u00e9s <a rel=\"nofollow noopener\" href=\"https:\/\/www.npmjs.com\/package\/warbeast2000\" target=\"_blank\">b\u00eate de guerre2000<\/a> et <a rel=\"nofollow noopener\" href=\"https:\/\/www.npmjs.com\/package\/kodiak2k\" target=\"_blank\">kodiak2k<\/a> ont \u00e9t\u00e9 publi\u00e9s au d\u00e9but du mois, attirant <a rel=\"nofollow noopener\" href=\"https:\/\/npm-stat.com\/charts.html?package=warbeast2000\" target=\"_blank\">412<\/a> et <a rel=\"nofollow noopener\" href=\"https:\/\/npm-stat.com\/charts.html?package=kodiak2k\" target=\"_blank\">1\u00a0281 t\u00e9l\u00e9chargements<\/a> avant qu&#8217;ils ne soient supprim\u00e9s par les responsables de npm.  Les t\u00e9l\u00e9chargements les plus r\u00e9cents ont eu lieu le 21 janvier 2024.<\/p>\n<p>La soci\u00e9t\u00e9 de s\u00e9curit\u00e9 de la cha\u00eene d&#8217;approvisionnement en logiciels ReversingLabs, qui a fait la d\u00e9couverte, a d\u00e9clar\u00e9 qu&#8217;il existait huit versions diff\u00e9rentes de warbeast2000 et plus de 30 versions de kodiak2k.<\/p>\n<p>Les deux modules sont con\u00e7us pour ex\u00e9cuter un script de post-installation apr\u00e8s l&#8217;installation, con\u00e7u pour r\u00e9cup\u00e9rer et ex\u00e9cuter deux fichiers JavaScript diff\u00e9rents.<\/p>\n<div class=\"check_two clear babsi\"><center class=\"cf\"><a rel=\"nofollow noopener\" href=\"https:\/\/thn.news\/tl_d1\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"La cyber-s\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/01\/Les-attaques-DDoS-contre-le-secteur-des-services-environnementaux-augmentent.gif\" width=\"727\" height=\"90\"\/><\/a><\/center><\/div>\n<p>Alors que warbeast2000 tente d&#8217;acc\u00e9der \u00e0 la cl\u00e9 priv\u00e9e SSH, kodiak2k est con\u00e7u pour rechercher une cl\u00e9 nomm\u00e9e \u00ab\u00a0meow\u00a0\u00bb, ce qui soul\u00e8ve la possibilit\u00e9 que l&#8217;acteur malveillant ait probablement utilis\u00e9 un nom d&#8217;espace r\u00e9serv\u00e9 au cours des premi\u00e8res \u00e9tapes du d\u00e9veloppement.<\/p>\n<p>&#8220;Ce script malveillant de deuxi\u00e8me \u00e9tape lit la cl\u00e9 priv\u00e9e SSH stock\u00e9e dans le fichier id_rsa situ\u00e9 dans le r\u00e9pertoire <homedir>\/.ssh&#8221;, a d\u00e9clar\u00e9 la chercheuse en s\u00e9curit\u00e9 Lucija Valenti\u0107. <a rel=\"nofollow noopener\" href=\"https:\/\/www.reversinglabs.com\/blog\/gitgot-cybercriminals-using-github-to-store-stolen-data\" target=\"_blank\">dit<\/a>.  &#8220;Il a ensuite t\u00e9l\u00e9charg\u00e9 la cl\u00e9 cod\u00e9e en Base64 vers un r\u00e9f\u00e9rentiel GitHub contr\u00f4l\u00e9 par un attaquant.&#8221;<\/p>\n<p>Il a \u00e9t\u00e9 constat\u00e9 que les versions ult\u00e9rieures de kodiak2k ex\u00e9cutaient un script trouv\u00e9 dans un projet GitHub archiv\u00e9 h\u00e9bergeant le <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/EmpireProject\/Empire\" target=\"_blank\">Empire<\/a> cadre post-exploitation.  Le script est capable de lancer le <a rel=\"nofollow noopener\" href=\"https:\/\/attack.mitre.org\/software\/S0002\/\" target=\"_blank\">Mimikatz<\/a> outil de piratage pour vider les informations d&#8217;identification de la m\u00e9moire du processus.<\/p>\n<p>&#8220;Cette campagne n&#8217;est que le dernier exemple de cybercriminels et d&#8217;acteurs malveillants utilisant des gestionnaires de packages open source et l&#8217;infrastructure associ\u00e9e pour soutenir des campagnes de cha\u00eene d&#8217;approvisionnement de logiciels malveillants ciblant les organisations de d\u00e9veloppement et les organisations d&#8217;utilisateurs finaux&#8221;, a d\u00e9clar\u00e9 Valenti\u0107.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2024\/01\/malicious-npm-packages-exfiltrate-1600.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80223 janvier 2024\ue804R\u00e9dactionS\u00e9curit\u00e9 logicielle \/ Cha\u00eene d&#8217;approvisionnement Il a \u00e9t\u00e9 d\u00e9couvert que deux packages malveillants d\u00e9couverts dans le registre des packages npm exploitaient GitHub pour stocker les cl\u00e9s SSH crypt\u00e9es en Base64 vol\u00e9es sur les syst\u00e8mes de d\u00e9veloppement sur lesquels ils \u00e9taient install\u00e9s. Les modules nomm\u00e9s b\u00eate de guerre2000 et kodiak2k ont \u00e9t\u00e9 publi\u00e9s au [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1114463,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[200292,1556,6208,4168,4165,4161,200267,133,38644,225948,50438,4159,4171,200271,4590,200268,200269,200270,7310,7309,128318,4172,4169,97596,4166,4164],"class_list":["post-1114462","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-actualites-sur-la-cybersecurite","tag-centaines","tag-cles","tag-comment-pirater","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-cyberactualites","tag-des","tag-developpeur","tag-exfiltrent","tag-github","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-logiciel-malveillant-rancongiciel","tag-malveillants","tag-mises-a-jour-sur-la-cybersecurite","tag-nouvelles-des-pirates","tag-nouvelles-sur-le-piratage","tag-npm","tag-packages","tag-securite-des-informations","tag-securite-informatique","tag-securite-internet","tag-ssh","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1114462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=1114462"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1114462\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/1114463"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=1114462"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=1114462"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=1114462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}