Discovered in early 2025, several malicious npm packages have been masquerading as legitimate Telegram bot libraries to deliver SSH backdoors and exfiltrate sensitive data from unsuspecting developers. The malicious variants—node-telegram-utils, node-telegram-bots-api, and node-telegram-util—appear virtually identical to the legitimate package, copying its documentation, functionality, and even linking back to the authentic GitHub repository with its 19,000+ stars to enhance credibility and deceive developers. Socket.dev researchers identified that these packages implement a sophisticated “starjacking” technique, where they link their homepage back to the legitimate GitHub repository to borrow trust from the original project’s reputation. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. This deception makes the malicious packages particularly difficult to identify during casual inspection, as they display the same star count as the legitimate library. The code not only injects multiple SSH keys for redundant access but also exfiltrates the victim’s IP address and username to a command-and-control server at solana[.]validator[.]blog, allowing attackers to inventory compromised systems for further exploitation or data theft. Upon installation in a Linux environment, the malicious packages automatically execute a hidden function called addBotId() whenever the constructor is called. These typosquatted packages collectively accumulated approximately 300 downloads over several months, creating a significant security threat despite their relatively modest installation numbers. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news. This function performs a platform check and, if Linux is detected, proceeds with its malicious payload without requiring any user interaction. Tushar is a Cyber security content editor with a passion for creating captivating and informative content. A concerning new supply chain attack has emerged targeting Linux developers who work with Telegram’s bot ecosystem. The attack specifically targets developer environments where npm packages are frequently installed during project setup or maintenance.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 22 Apr 2025 20:30:07 +0000