[ << ALL_FEED ]

Did someone say sandbox?

More in General

Someone said sandbox? 👀

Once again we’re watching threat actors conduct unethical research.

Given:
Security researcher Nicholas Curran

He published packages with interesting names:
🌟2 packages npm-sandbox-ping-[4 characters]
🌟8 packages npm-sandbox-research-[4 characters]
🌟postinstall-logger-7x9z
🌟pkg-telemetry-r4f9
🌟runtime-metrics-w7k2
🌟event-metrics-q3x7
🌟build-tracker-n5p1

According to the description (screenshot 1), these packages were created as part of a bug bounty program.

The author claims that:
🔗The packages are safe.
🔗All sensitive data is hashed before being sent — no secrets are disclosed.
🔗The packages do not establish persistence on the system, move laterally across the network, or perform destructive actions.
🔗The goal of the research: to study whether the npm sandbox isolates unsafe installation scripts.

Sandbox security research? We love that. Let’s take a look at how it’s implemented.

The payload starts twice: before and after package installation (screenshot 2). Windows logic is handled by beaconXX.js, all other platforms are handled by beacon_linux.js. Even macOS.

Logic under Windows

beaconXX.js (screenshot 3):
1️⃣ Exploits a known UAC bypass via fodhelper.exe. To do this, in addition to launching the file, it is necessary to make changes to the Windows registry.
2️⃣ Drops a PowerShell script into %TEMP% and runs it with elevated privileges.

PowerShell script:
1️⃣ Removes the changes made to the registry.
2️⃣ Collects:
🐟 artifacts specific to the sandbox being studied from drive D, including the file findings.xml;
🐟 a list of secrets from Credential Manager;
🐟 npm config list — this includes authentication tokens for the npm account;
🐟 all environment variables.
3️⃣ Covers its tracks by overwriting findings.xml with the following text:

<ArrayOfTaskFinding></ArrayOfTaskFinding>

4️⃣ Encodes the collected data in base64 and simply sends it to the command-and-control server… without the hashing stated in README.md 🤪
5️⃣ In an infinite loop, every 5 seconds it contacts the command-and-control server for commands to execute.

Given how the code tries to interfere with the sandbox’s operation, we can assume this is a custom sandbox with an agent similar to Cuckoo Sandbox.

Logic under non-Windows

beacon_linux.js (screenshot 4):
1️⃣ Collects:
🐟 a list of the names of all environment variables;
🐟 the values of interesting environment variables related to GitHub, NPM, runners, and the user;
🐟 a list of network interfaces.
2️⃣ Checks for container escape opportunities by collecting:
🐟 the contents of /proc/1/cgroup (information about container restrictions);
🐟 the command line of the process with PID 1;
🐟 a list of mounted volumes.
🐟 the set of capabilities of its own process;
🐟 the presence of /var/run/docker.sock (allows controlling Docker with the potential to fully take over the device);
🐟 access to /proc/sched_debug (allows reconnaissance of processes running on the host).
3️⃣ Collects CI/CD-related artifacts: a list of files in the current project and /home/runner/work, GitHub logs.
4️⃣ Sends the report to the command-and-control server.

Conclusion

The packages do not match the good intentions declared to us in README.md — so we reported this misunderstanding to the NPM admins.

It’s strange to see such behavior from a bug hunter who has had a HackerOne account since 2017 🤔

Want to check your projects for malicious external dependencies? Try the secure development feeds from PT Fusion.

#ti #scs #npm
@ptescalator

More from ti_author

More from ti_author

More in General