Joint research of Checkmarx and Illustria resulted with an anomaly discovered in the open-source ecosystem
Over 144,000 packages were published to NuGet, NPM, and PyPi by the same threat actors
Investigation revealed a new attack vector — attackers spam open-source ecosystem with packages containing links to phishing campaigns
All packages and related user accounts were most likely created using automation
The threat actors refer to retail websites with referral ids to benefit the threat actors with referral rewards
Our teams disclosed the findings in this report and most of the packages were unlisted
https://illustria.io
/ illustria-checkmarx-finds-140k-phishing-pa...