<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ransomware Archivi - Webbare</title>
	<atom:link href="https://www.webbare.it/tag/ransomware/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.webbare.it/tag/ransomware/</link>
	<description>Easy choise, easy way!</description>
	<lastBuildDate>Wed, 14 Dec 2022 13:13:26 +0000</lastBuildDate>
	<language>it-IT</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://www.webbare.it/wp-content/uploads/2020/02/jira-logo-scaled.png</url>
	<title>ransomware Archivi - Webbare</title>
	<link>https://www.webbare.it/tag/ransomware/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Una campagna malware prende di mira i repository Python e JavaScript ufficiali</title>
		<link>https://www.webbare.it/2022-12-malware-repository-python-javascript/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=malware-repository-python-javascript</link>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Wed, 14 Dec 2022 13:13:26 +0000</pubDate>
				<category><![CDATA[Dev]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Web Developer]]></category>
		<category><![CDATA[Web Marketing]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phylum]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[repository]]></category>
		<guid isPermaLink="false">https://www.webbare.it/?p=2040</guid>

					<description><![CDATA[<p>L'articolo <a href="https://www.webbare.it/2022-12-malware-repository-python-javascript/">Una campagna malware prende di mira i repository Python e JavaScript ufficiali</a> proviene da <a href="https://www.webbare.it">Webbare</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper" id="wpb-content-root"><div id="vc_row-6a9b558bded41" class="vc_row wpb_row vc_row-fluid thegem-custom-6a9b558bdecf93814"><div class="wpb_column vc_column_container vc_col-sm-12 thegem-custom-6a9b558be73305043" ><div class="vc_column-inner thegem-custom-inner-6a9b558be7333 "><div class="wpb_wrapper thegem-custom-6a9b558be73305043">
	
		<div class="wpb_text_column wpb_content_element  thegem-vc-text thegem-custom-6a9b558be79556155"  >
			<div class="wpb_wrapper">
				<p>Una campagna di <strong>malware</strong> attiva prende di mira i repository ufficiali di <strong>Python</strong> e <strong>JavaScript</strong>.</p>
<p>La società di sicurezza della catena di fornitura di software <strong>Phylum</strong> ha individuato la campagna. Phylum ha affermato di aver scoperto la campagna dopo aver notato una raffica di attività attorno ai <em>typosquat</em> del popolare pacchetto di richieste Python.</p>
<p>I <em>typosquat</em> sfruttano semplici errori di battitura per installare pacchetti dannosi.</p>
<p>In questo caso, i typos <strong>PyPI</strong> includono: d<em>equests, fequests, gequests, rdquests, reauests, reduests, reeuests, reqhests, reqkests, requesfs, requesta, requeste, requestw, requfsts, resuests, rewuests, rfquests, rrquests, rwquests, telnservrr e tequest.</em></p>
<p>Phylum in seguito ha scoperto che l&#8217;attaccante stava pubblicando i seguenti pacchetti <strong>NPM</strong> che sfruttano anch&#8217;essi il typosquatting: discordallintsbot, discordselfbot16, discord-all-intents-bot, discors.jd e telnservrr.</p>
<p>In quanto cloni delle biblioteche ufficiali, spesso passano inosservati finché non è troppo tardi.</p>
<p>A seconda del sistema operativo del dispositivo della vittima, questo particolare malware scarica un binario Golang rilevante. Una volta eseguito, lo sfondo del desktop del computer della vittima viene aggiornato con una falsa immagine della CIA e il malware tenterà di crittografare alcuni file.</p>
<p>Un file README viene inserito dal malware sul desktop che chiede all&#8217;utente di contattare l&#8217;individuo su Telegram e pagare <em>&#8220;una piccola quota di $ 100&#8221;</em> in BTC, ETH, LTC o XMR. In caso contrario, l&#8217;attaccante afferma che la chiave di decrittazione verrà cancellata.</p>
<p>Secondo <strong>Phylum</strong>, l&#8217;attacco è in corso (dal 13 dicembre 2022) ma è stata rilasciata una nuova versione del <strong>ransomware</strong> che ha anche limitato le architetture supportate.</p>

			</div>
			<style>@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b558be79556155{display: block!important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b558be79556155{display: block!important;}}@media screen and (max-width: 1023px) {.thegem-vc-text.thegem-custom-6a9b558be79556155{position: relative !important;}}@media screen and (max-width: 767px) {.thegem-vc-text.thegem-custom-6a9b558be79556155{position: relative !important;}}</style>
		</div>
	
</div></div></div></div>
</div><p>L'articolo <a href="https://www.webbare.it/2022-12-malware-repository-python-javascript/">Una campagna malware prende di mira i repository Python e JavaScript ufficiali</a> proviene da <a href="https://www.webbare.it">Webbare</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
