corepack[.]org is impersonating the Corepack Node.js tool to lure developers into downloading malicious executables that install an infostealer and enroll victims in proxyware bandwidth sharing. The fake site also uses a separate redirect chain to deliver adware or trojan activity, while the real Corepack project has no official website at corepack.org. #Corepack #Nodejs #OpenShield #OperaGXSetup

Keypoints

  • corepack[.]org is a fake site impersonating Corepack, a Node.js package manager tool, to target developers searching for a download.
  • The real Corepack is not distributed as a Windows installer and has no official website at corepack.org.
  • Clicking the site’s “Download Free” button leads to an OpenShield page that drops vpnsetup_d9gfqvs3dsic73fcvi90.exe.
  • The OpenShield payload is classified as an infostealer and performs browser-profile theft, SSH key access, discovery, command execution, and persistence.
  • The malware also enrolls infected systems in bandwidth-sharing proxy activity, effectively turning them into proxy exit nodes.
  • A second delivery path uses a fake download page to push OperaGXSetup.exe and is associated with adware-style and trojan activity.
  • Node.js contributors reported the domain, and maintainer and registrar abuse actions were initiated after downloads appeared.

MITRE Techniques

  • [T1566 ] Phishing – The site impersonates a trusted developer tool to lure victims into downloading malicious files (‘developers who land on the page looking for a download’).
  • [T1036 ] Masquerading – The domain pretends to be Corepack and presents fake downloads to appear legitimate (‘impersonating Corepack’ and ‘Any download offered there should be treated as malicious’).
  • [T1204 ] User Execution – The attack depends on the victim clicking download and running the executable (‘Clicking “Download Free”… downloads a file’ and ‘When executed’).
  • [T1105 ] Ingress Tool Transfer – The malicious executable is delivered from the fake site to the victim machine (‘downloads a file named vpnsetup_d9gfqvs3dsic73fcvi90.exe’).
  • [T1059.001 ] PowerShell – The payload performs PowerShell execution on the infected host (‘PowerShell and command-shell execution’).
  • [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell – The payload uses the command shell for execution (‘PowerShell and command-shell execution’).
  • [T1082 ] System Information Discovery – The malware performs host and process discovery (‘Host and process discovery’).
  • [T1005 ] Data from Local System – The payload accesses browser-profile data and stored SSH keys (‘Access to browser-profile data and stored SSH keys’).
  • [T1547.001 ] Registry Run Keys / Startup Folder – Persistence is established through run keys to survive reboots (‘Run-key persistence to survive reboots’).

Indicators of Compromise

  • [File names ] Malicious downloads delivered from the fake Corepack site – vpnsetup_d9gfqvs3dsic73fcvi90[.]exe, OperaGXSetup[.]exe
  • [Domains ] Phishing and malware-delivery infrastructure – corepack[.]org, openshield[.]canatrace[.]com
  • [URLs ] Redirect and download pages used in the delivery chain – /download-free-can/freevpn[.]win/lps/gbox-lp/index[.]html, moonlighthathel[.]org
  • [Domains ] Additional infrastructure linked to the campaign – aifpleasurebeh[.]org, ghabovethec[.]info, ukankingwithea[.]com, beadpie[.]xyz, yakteam[.]xyz, nostop[.]go2cloud[.]org


Read more: https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-proxyware