5 ms·
What did the phishing email say that made you click and login?
by nodesocket 1y ago
What did the phishing email say that made you click and login?
- junon 1y agoThat it had been more than 12 months since last updating them. Npm has done outreach before about doing security changes/enhancements in the past so this didn't really catch me. Screenshot here: https://imgur.com/a/q8s235k https://imgur.com/a/q8s235k
- SSLy 1y agoCan you post full message headers somewhere? It'd be interesting which MTA was involved in delivery from the sender's side.
- junon 1y agoYep - https://gist.github.com/Qix-/c1f0d4f0d359dffaeec48dbfa1d40ee9 https://gist.github.com/Qix-/c1f0d4f0d359dffaeec48dbfa1d40ee...
- SSLy 1y agolet's see the header of interest: Received: from npmjs.help by smtp.mailtrap.live
- XxgodReixX88 1y agowhat about it?
- alexellisuk 1y agoHow did simply opening this email in something like Gmail or a desktop client result in it being able to compromise NPM packages under your control? I'm just curious - and as a word of warning to others so we can learn. I may be missing some details, I've read most of the comments on the page.
- junon 1y agoI clicked the link like a genius :)
- alexellisuk 1y ago:-( How did the link hijack your password/2fa? Or did you also enter some stuff on the form?
- osa1 1y agoI don't understand. The link could've come from anywhere (for example from a HN comment). How does just clicking on it give your package credentials to someone else? Is NPM also at fault here? I'd naively think that this shouldn't be possible. For example, GitHub asks for 2FA when I change certain repo settings (or when deleting a repo etc.) even when I'm logged in. Maybe NPM needs to do the same?
- koil 1y agoAs OC mentioned elsewhere, it was a targeted TOTP proxy attack.
- hughw 1y agoSo, he clicked the link and then entered his correct TOTP? how would manually typing the url instead of clicking the link have mitigated this?
- Mogzol 1y agoThey wouldn't have manually typed the exact URL from the email, they would have just typed in npmjs.com which would ensure they ended up on the real NPM site. Or even if they did type out the exact URL from the email, it would have made them much more likely to notice that it was not the real NPM URL.
- dboreham 1y agoOP entered their credentials and TOTP code, which the attacker proxied to the real npmjs.com FWIW npmjs does support FIDO2 including hard tokens like Yubikey. They do not force re-auth when issuing an access token with publish rights, which is probably how the attackers compromised the packages. iirc GitHub does force re-auth when you request an access token.
- nsdfg 1y agohttps://mailtrap.io/contact-details/ https://mailtrap.io/contact-details/
- nodesocket 1y agoYikes, looks legit. Curious what are the destination addresses? Would like to monitor them to see how much coin they are stealing.
- hunter2_ 1y agoIn terms of presentation, yes. In terms of substance, short deadlines are often what separate phishing from legitimate requests.
- mrguyorama 1y agoThere is NO reliable indicators, because every single one of these "Legit requests don't ..." recommendations has been done by a local bank trying to get their customers to do something. My local credit union sent me a "please change your password" email from a completely unassociated email address with a link to the change password portal. I emailed them saying "Hey it looks like someone is phishing" and they said, "nope, we really, intentionally, did this" Companies intentionally withhold warning emails as late as possible to cause more people to incur late fees. So everyone is used to "shit, gotta do this now or get screwed" You can't hope to have good security when everyone's money is controlled by organizations that actively train people to have bad OPSEC or risk missing rent.
- hunter2_ 1y agoI agree: any of the potential indicators of phishing (whether it's poor presentation, incorrect grammar, tight deadlines, unusual "from" addresses, unusual domains in links, etc.) can easily have false positives which unfortunately dull people's senses. That doesn't mean they can't continue to be promulgated as indicators of possible (not definite) phishing, though. I used the word "often" rather than "always" for this reason.
- cataflam 1y ago> There is NO reliable indicators Completely agree. The only reliable way is to never use an email/SMS link to login, ever.
- bflesch 1y agoThanks for sharing, I've created an OTX entry for this: https://otx.alienvault.com/pulse/68bf031ee0452072533deee6 https://otx.alienvault.com/pulse/68bf031ee0452072533deee6
- dgl 1y agoJust looking for "const _0x112" as an IOC seems a bit false positive prone: https://github.com/search?q=%2Fconst+_0x112%2F+lang%3Ajs&type=code https://github.com/search?q=%2Fconst+_0x112%2F+lang%3Ajs&typ... (most of that code is pretty dodgy obviously, but it's not unique enough to identify this).
- twoodfin 1y agoPerfect example of why habituating users to renewing credentials (typically password expiration) is a terrible practice.
- anonymars 1y agoFrustrating that you're being downvoted https://pages.nist.gov/800-63-FAQ/#q-b05 https://pages.nist.gov/800-63-FAQ/#q-b05
- NooneAtAll3 1y agois there an actual habituation? that message feels like it could work as a first-time as well
- twoodfin 1y agoWe should be immediately suspicious when we get any solicitation to "renew" something "expired" in a security domain. Swapping un-compromised secrets is essentially always more risky than leaving them be. Regardless of whether the real NPM had done this in the past, decades of dumb password expiration policies have trained us that requests like this are to be expected rather than suspected.
- nicoburns 1y agoIf legitimate companies didn't do this, then the email would be suspicious.
- deleted 1y ago[deleted]
- lifeinthevoid 1y agoThat green checkmark ... what application is this?
- junon 1y agoMigadu. The tooltip hovering over it shows: dkim=pass header.d=smtp.mailtrap.live header.s=rwmt1 header.b=Wrv0sR0r
- markasoftware 1y agocheck marks in email clients usually mean DKIM / other domain verification passed. The attack author truly owns npmjs.help, so a checkmark is appropriate.
- rollcat 1y ago@everyone in the industry, everywhere: Urgency is poison. Please, please put a foot in the door whenever you see anyone trying to push this kind of sh*t on your users. Make one month's advance notice the golden standard. I see this pattern in scam mail (including physical) all the time: stamp an unreasonably short notice and expect the mark to panic. This scam works - and this is why legit companies that try this "in good faith" should be shamed for doing it. Actual alerts: just notify. Take immediate, preventive, but non-destructive action, and help the user figure out how to right it - on their own terms.
- notmyjob 1y agoAgree, but this example wasn’t even that aggressive in its urgency and op said they were merely ticking things off the todo, not feeling alarmed by the urgency. The problem is email as it’s used currently. The solution is to not use email.
- niwtsol 1y agoThe email says accounts will start locking Sept 10th and it was sent Sept 8th - so a 48 hour urgency window or an account would be locked is urgency IMO
- notmyjob 1y agoFair enough, was just thinking about many low effort scams that have “EMERGENCY!!! ACT NOW!!!” in red boldface. This, by being slightly? less aggressive is actually less likely to trip my “this is phishing” detector. Obviously ymmv.
- deleted 1y ago[deleted]
- naikrovek 1y ago> The solution is to not use email. and use what? instant message? few things lack legitimacy more than an instant message asking you to do something. Links in email are much more of a problem than email itself. So tempting to click. It's right there, you don't have to dig through bookmarks, you don't have to remember anything, just click. A link is seductive. the actual solution is to avoid dependencies whenever possible, so that you can review them when they change. You depend on them. You ARE reviewing them, right? Fewer things to depend on is better than more, and NPM is very much an ecosystem where one is encouraged to depend on others as much as possible.
- IshKebab 1y agoAnd then what happens when you click the link? Wouldn't your password manager fail to auto fill your details?
- junon 1y agoThis was mobile, I don't use browser extensions for the password manager there.