3 ms·
I've not tried this, but a similar but easier exploit would be to register packages with names that are close to existing popular package names, and then have a
by jtuchsen 11y ago
I've not tried this, but a similar but easier exploit would be to register packages with names that are close to existing popular package names, and then have a post install script inject a modified version of the actual package into the node_modules directory that also does something malicious. So you register the "lodasj" package instead of "lodash" and than create a post install script to inject the malicious "lodash" package that re-exports all of the lodash API + does something nasty. If someone has a typo with "npm i lodasj" and doesn't notice the mistake, the machine that installs it and anyone that depends on the package is infected. I wonder how well policed NPM is against these kinds of malware attacks.
- troygoode 11y agothey'd notice as soon as they tried to run their program as "import * from 'lodash'" would fail (unless they were consistent with their typos...)
- tyingq 11y agoThis one isn't doing anything scary at the moment, but shows the potential: https://www.npmjs.com/package/uglifyjs https://www.npmjs.com/package/uglifyjs It's getting 30k+ downloads a month. The actual package people are looking for is here: https://www.npmjs.com/package/uglify-js https://www.npmjs.com/package/uglify-js