Malware & Info-Stealers 2018 Incident #42

getcookies backdoor chain

Estimated Financial Impact
64K weekly downloads (mailparser)
Blast Radius
Nested dependency chain; HTTP header C2

What Happened

A sophisticated backdoor hidden in a nested dependency chain: mailparser → http-fetch-cookies → express-cookies → getcookies. The backdoor parsed HTTP headers for RCE commands. mailparser had ~64,000 weekly downloads. Caught before widespread exploitation.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTS

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← Fortinet WS campaign RubyGems mass typosquatting →