Linchakin

Package Analysis – OpenSSf Tool to Detect Malicious Packages in Popular Open-Source Repositories

 May 02, 2022     No comments   

Package Analysis – OpenSSf Tool to Detect Malicious Packages in Popular Open-Source Repositories

A prototype version of the Package Analysis tool has been recently released by the Open Source Security Foundation (OpenSSF), and it is the first of its kind to be published.

Using this tool, you can identify malicious attacks against open source registries in real-time and counter them. A short period of time after its release on GitHub, this tool identified more than 200 malicious packages using npm and PyPI in a pilot run that lasted less than a month.

This project analyses the packages found in open source repositories to find out:- 

  • How do they behave? 
  • What capabilities do they have?
  • What files do they access?
  • What addresses do they connect to?
  • What commands do they run?

Robust Tool to Scan open-source Repositories

This repository houses tools which are used to analyze open-source software packages, in particular, malware in the following packages:- 

  • npm packages
  • PyPI packages

As a result of this effort, open-source software will be better protected through the following reporting:-

  • Detecting malicious behavior.
  • Informing consumers selecting packages.
  • Providing researchers with data about the ecosystem.

There is one malicious package that has been identified by Package Analysis among all the suspect packages: ‘colorsss’. While this package has been found to be formerly deemed malicious.

Almost all of the packages that have been found contain a simple script that runs and requests a few details about the host from home during an installation process.

In most cases, these packages are created by security researchers looking to find bug bounties as part of a bug bounty program.

There is no attempt to conceal their behavior, and the majority of them are capable of extracting meaningful information from the system like:-

  • Name of the machine/system
  • Username

Future Goals

Here below we have mentioned all the future goals of the Package Analysis tool:-

  • The ability to detect changes in package behavior over time.
  • The packaging analysis results can be processed automatically after they have been received.
  • In order to maintain long-term analysis of the stored packages, they are stored themselves as they are processed.
  • The pipeline will gain greater reliability by improving its efficiency of the pipeline.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Samsung's foldable phone launch proves there's still a need for the Galaxy S21 FEEven with Galaxy Z Fold 3 and Galaxy Z Flip 3, the rumored Galaxy S21...It was certainly a big week for Samsung, which rolled out two new foldable phones that — at first glance, anyhow — seem to be improvements over their … Read More
  • CamPhish - Grab Cam Shots From Target'S Phone Front Camera Or PC Webcam Just Sending A Link. Grab cam shots from target's phone front camera or PC webcam just sending a link.  What is CamPhish? CamPhish is techniques to take cam shots o… Read More
  • 16th Aug - MSME MSME stands for Micro, Small and Medium Enterprises. This is the organization responsible for the manufacturing, development, and preservation of goo… Read More
  • TechFacebook Messenger calls and Instagram DMs get encryption, but only if you opt inWith video calls taking hold as a major part of our lives during a way-too-long pandemic, Facebook is doing a little bit more to protect those made on… Read More
  • Google Pixel Fold tipped to get this Pixel 6 super chipAndroid 12 analysis suggests the rumored Pixel Fold could get the same Tensor chip as the Pixel... The Android 12 beta continues to provide possible insights into Google’s future hardware moves — with the latest report suggesting that the rumored G… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates