corepack[.]org is impersonating the Corepack Node.js tool to lure developers into downloading malicious executables that install an infostealer and enroll victims in proxyware bandwidth sharing. The fake site also uses a separate redirect chain to deliver adware or trojan activity, while the real Corepack project has no official website at corepack.org. #Corepack #Nodejs #OpenShield #OperaGXSetup
Keypoints
- corepack[.]org is a fake site impersonating Corepack, a Node.js package manager tool, to target developers searching for a download.
- The real Corepack is not distributed as a Windows installer and has no official website at corepack.org.
- Clicking the siteâs âDownload Freeâ button leads to an OpenShield page that drops vpnsetup_d9gfqvs3dsic73fcvi90.exe.
- The OpenShield payload is classified as an infostealer and performs browser-profile theft, SSH key access, discovery, command execution, and persistence.
- The malware also enrolls infected systems in bandwidth-sharing proxy activity, effectively turning them into proxy exit nodes.
- A second delivery path uses a fake download page to push OperaGXSetup.exe and is associated with adware-style and trojan activity.
- Node.js contributors reported the domain, and maintainer and registrar abuse actions were initiated after downloads appeared.
MITRE Techniques
- [T1566 ] Phishing â The site impersonates a trusted developer tool to lure victims into downloading malicious files (âdevelopers who land on the page looking for a downloadâ).
- [T1036 ] Masquerading â The domain pretends to be Corepack and presents fake downloads to appear legitimate (âimpersonating Corepackâ and âAny download offered there should be treated as maliciousâ).
- [T1204 ] User Execution â The attack depends on the victim clicking download and running the executable (âClicking âDownload Freeâ⌠downloads a fileâ and âWhen executedâ).
- [T1105 ] Ingress Tool Transfer â The malicious executable is delivered from the fake site to the victim machine (âdownloads a file named vpnsetup_d9gfqvs3dsic73fcvi90.exeâ).
- [T1059.001 ] PowerShell â The payload performs PowerShell execution on the infected host (âPowerShell and command-shell executionâ).
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell â The payload uses the command shell for execution (âPowerShell and command-shell executionâ).
- [T1082 ] System Information Discovery â The malware performs host and process discovery (âHost and process discoveryâ).
- [T1005 ] Data from Local System â The payload accesses browser-profile data and stored SSH keys (âAccess to browser-profile data and stored SSH keysâ).
- [T1547.001 ] Registry Run Keys / Startup Folder â Persistence is established through run keys to survive reboots (âRun-key persistence to survive rebootsâ).
Indicators of Compromise
- [File names ] Malicious downloads delivered from the fake Corepack site â vpnsetup_d9gfqvs3dsic73fcvi90[.]exe, OperaGXSetup[.]exe
- [Domains ] Phishing and malware-delivery infrastructure â corepack[.]org, openshield[.]canatrace[.]com
- [URLs ] Redirect and download pages used in the delivery chain â /download-free-can/freevpn[.]win/lps/gbox-lp/index[.]html, moonlighthathel[.]org
- [Domains ] Additional infrastructure linked to the campaign â aifpleasurebeh[.]org, ghabovethec[.]info, ukankingwithea[.]com, beadpie[.]xyz, yakteam[.]xyz, nostop[.]go2cloud[.]org
Read more: https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware