Skip to main content

TH17134

Detected presence of files containing URLs that are used to distribute hacktools.

priorityCI/CD statusseverityeffortSAFE levelSAFE assessment
failhighhigh1tampering: fail
Reason: restricted network references

About the issueโ€‹

Uniform Resource Locators (URLs) are structured addresses that point to locations and assets on the internet. URLs allow software developers to build complex applications that exchange data with servers that can be hosted in multiple geographical regions. URLs can commonly be found embedded in documentation, configuration files, source code and compiled binaries. One or more embedded URLs were discovered to link to an address known to distribute hacking tools. Hacking tools are commonly used by malicious actors to bypass security solutions, exploit system weaknesses, collect personal information, and exfiltrate data. Software components that contain links to network locations distributing hacking tools are reported as malicious.

How to resolve the issueโ€‹

  • Investigate reported detections.
  • Consult Mitre ATT&CK documentation: T1588.002 - Obtain Capabilities: Tool.
  • If the software should not include these network references, investigate your build and release environment for software supply chain compromise.
  • You should delay the software release until the investigation is completed, or until the issue is risk accepted.
  • Remove all references to flagged network locations.

Incidence statisticsโ€‹

ReversingLabs periodically collects and analyzes the contents of popular software package repositories for threat research purposes. Analysis results are used to calculate incidence statistics for issues (policy violations) that Spectra Assure can detect in software packages.

This section is updated when new data becomes available.

Total amount of packages analyzed

  • Linux: 562K
  • NPM: 5.12M
  • Nuget: 735K
  • PS Gallery: 17K
  • PyPi: 838K
  • RubyGems: 203K
  • VS Code: 113K
  • Windows: 3.7K
Statistics are not collected for the TH17134 policy at this time, or not applicable to this type of issue.