timb-machine / timb-machine/linux-malware
[Intel]: https://blog.sonatype.com/newly-found-npm-malware-mines-cryptocurrency-on-windows-linux-macos-devices
Open
Nobody has claimed this yet.
missing:tag:PyPI
missing:tag:T1005
missing:tag:T1021.002
missing:tag:T1048
missing:tag:T1057
missing:tag:T1070.003
missing:tag:T1070.004
missing:tag:T1071.001
missing:tag:T1491
missing:tag:T1546.004
missing:tag:T1552.003
missing:tag:T1567
missing:tag:T1573
missing:tag:T1574.007
missing:tag:T1590
new
- Dominant language
- HTML
- Stars
- 1.2k
- Forks
- 95
- PR merge metrics
- No merged PRs in 30d
Description
Area
Supply chain attacks
Parent threat
Impact
Finding
Industry reference
delivery:NPM
uses:JavaScript
attack:T1195.001:Compromise Software Dependencies and Development Tools
Malware reference
wltm
Actor reference
No response
Component
No response
Scenario
No response
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked Sonatype report about the wltm npm malware and compare its details with existing entries in this repository. Done means documenting this finding with the supplied supply-chain, npm, JavaScript, ATT&CK, and malware references.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100