18 ms·
Malicious crossenv package on npm
- eropple 9y agoThis is important. It looks like the organization is submerging; they've deleted their NPM account and the package and emptied their GitHub repo. This should be signal boosted as hard as it can be managed, because this is rough stuff.
- codefined 9y agoWhat can be done to help sort problems like this?
- eropple 9y agoTo be honest? I don't know. Bugs (or malicious end-runs) are only shallow with many eyes, and none of this has eyes on it.
- tedunangst 9y agoGardens. With gardeners. And walls.
- i_am_nomad 9y agoAnd money for all three.
- deleted 9y ago[deleted]
- tedunangst 9y agonpm has about $10 million, so that shouldn't be a problem.
- kimburgess 9y agoIntegrating something like https://nodesecurity.io/opensource https://nodesecurity.io/opensource or https://snyk.io https://snyk.io into you're CI process will help flag issues you may want to know about if they are disclosed / discovered. And yes, I get the irony of adding another dependency to help with the security mess caused by the node ecosystem's bent towards external untrusted / unverified dependencies.
- Splines 9y agoNot a js dev, but it seems like when doing a compare if a package already exists, hyphens should be removed (so "crossenv" and "cross-env" are considered identical). "js" seems like needless verbosity, maybe take that out too. I wouldn't doubt that there are package names that would collide because of such a change, but that's probably a good thing. Does npm normalize package names with unicode in them? Would "сrοѕѕ-еnν" be considered equivalent? (Although this would only work if users copy/paste the name).
- unkown-unknowns 9y agoWhose NPM account? If you mean the attacker it was removed by the NPM people after it was reported.
- kevinsimper 9y agoThis is serious stuff and we will definitely see more of it in the future! As there are more and more node.js developers, it will be more profitable to run a scam like this and you only need to hijack one page that has a lot of dependencies, one package that is for example used by `express` to get access to a lot of users. The only thing you can do is be careful and listen for projects like node security.
- romanovcode 9y agoOr use some other technology.
- devwastaken 9y agoThis is something I've always been concerned about with the node/NPM environment. Any project, even the smallest ones, have hundreds of dependencies. All it takes is some small lines of rogue code, and your entire project is vulnerable. Especially in JS, where you can do network requests and various critical actions all in one line of code.
- colejohnson66 9y agoThe `left-pad` debacle a year ago[0] should've served as a wake up call to people writing projects with hundreds of dependencies. [0]: http://left-pad.io http://left-pad.io
- doingmyting 9y agoIt's next to impossible for the average team to avoid hundreds of dependencies as their project grows though. You could write your own everything, but then what's the benefit of the node ecosystem? Edit: spelling
- RandomInteger4 9y agoHow many of those dependancies are trivial though? It's one thing to rewrite express, but something different to rewrite a package that just contains a function that capitalizes the first letter of a string or something similarly contrived, yet plausibly already a package.
- jonknee 9y agoThat's the argument behind a stdlib of sorts for npm with blessed packages that are actively maintained and signed. Having every project rely on tons of dependencies isn't great, but re-writing everything a bunch of times also isn't great. There are bound to be bugs within 100 different implementations of X. It is certainly out of control though. I just checked the node_modules of a fresh create-react-app generated app and there are 877 packages! Tons of duplication here, like having both array-uniq and array-unique (not to mention that's a feature built into languages like Python).
- infinity0 9y agonodejs lack-of-QA comes back to bite them in the ass yet again. wasn't the first time nor will it be the last time, ditch this bullshit.
- eropple 9y agoExplain to me how "QA" prevents a malicious package from transitively including another one and taking advantage of typo squatting.
- tedunangst 9y agoQA prevents someone from adding a typo to the repository.
- eropple 9y agoYour QA teams are looking up every entry in your package.json files, your Maven poms, your Gemfiles, your requirements.txt files? They're making sure that something that builds completely cleanly and shows no external errors doesn't have a typo in it? Of course they're not.
- infinity0 9y agoThat's a pretty big straw man you wrote there, to imply that getting rid of not-all errors is no better than not getting rid of any errors at all. In fact, GNU/Linux distros with even minimal QA will disallow network access during builds. Also we do in fact manually audit quite a lot of stuff to make sure this sort of bullshit doesn't get uploaded to the archives.
- tedunangst 9y agoMy QA team, upon a request to add a package called "crossenv" to the npm repo, would say "this is suspiciously similar to the existing cross-env package. Request denied." Alas, npm has no such team.
- emeraldd 9y agoFor reference: https://twitter.com/o_cee/status/892306836199800836 https://twitter.com/o_cee/status/892306836199800836 since the user appears to have been nuked...
- shawnee_ 9y agoBetter link: https://pbs.twimg.com/media/DGK-eZ3WsAAvqN0.jpg:large https://pbs.twimg.com/media/DGK-eZ3WsAAvqN0.jpg:large
- deleted 9y ago[deleted]
- ben174 9y agoLooks like all the packages by this guy post to hacktask.net - a Chinese site. Google autocomplete also suggests xss.hacktask.net Looks like this guy is up to all kinds of no good.
- packetized 9y ago...hosted by Cloudflare.
- mrkrabo 9y agoDon't understand the downvotes. Cloudflare doesn't seem to have a problem hosting stuff like this, or even carders, and then ignoring abuse emails :')
- wolfgang42 9y agoThis attack has been previously described in the paper "Typosquatting package managers": Paper: http://incolumitas.com/data/thesis.pdf http://incolumitas.com/data/thesis.pdf Blog post: http://incolumitas.com/2016/06/08/typosquatting-package-managers/ http://incolumitas.com/2016/06/08/typosquatting-package-mana... Discussion: https://news.ycombinator.com/item?id=11862217 https://news.ycombinator.com/item?id=11862217 https://www.reddit.com/r/netsec/comments/4n4w2h/ https://www.reddit.com/r/netsec/comments/4n4w2h/ The paper also discusses possible mitigation measures, including prohibiting registering new packages within a certain Levenshtein distance of existing packages and using additional namespacing.
- hueving 9y agoNot really different from any other typo-squatting (e.g. domains).
- db48x 9y agoExcept that in this case you're installing software on your computer, not just visiting a webpage.
- boramalper 9y agoYou might also be downloading the software from a webpage. ;)
- pilif 9y agoThat would still be a two-step process (downloading from the browser and then manually executing it). `npm install` runs code as part of the initial step. Also, `npm install foo` will of course not just run code from `foo` but from all its dependencies and their dependencies dependencies as well.
- micaksica 9y agoThanks, I came here to post this exact thing. Even if NPM isn't prohibiting packages, you'd imagine they'd have internal security alerting for Levenshtein distance from the names of very popular npm packages. Such an alerting script wouldn't take terribly long to write (or to run). It'd let them catch this type of abuse much faster even if they decided (for some inane reason) that banning the names outright would break UX.
- phpnode 9y agoNPM themselves recently launched a new package called npx [0] which will download and execute packages directly from the registry if you don't already have them installed. So if you make a simple typo like this: npx crossenv foo instead of npx cross-env foo you'd have got the malicious version. [0] https://www.npmjs.com/package/npx https://www.npmjs.com/package/npx
- weetbix 9y agocrossenv was already running the script on post install, which means it was run on "npm i crossenv" anyway.
- phpnode 9y agopoint is that npm are encouraging you to use npx, which is bundled with npm 5.2+ as a general tool for executing adhoc commands from the terminal. It just massively increases the chance of typos.
- Spivak 9y agoAt some point there needs to be some trust, and NPM puts that boundary at installation. If you trust a package enough to install it, then it's allowed to act on your behalf with the permissions of your user. `npx` doesn't change that dynamic. It's no different than installing an RPM or Debian package over the internet.
- nulagrithom 9y agoImagine if Debian decided that `sduo rm *` meant it should apt-get install the sduo package and run immediately it. I know my systrems system wouldn't last 5 minutes.
- dboy1612 9y agoDoes anyone know if "hacktask.net" was used in all the rogue packages? Got a grep running through caches/projects.
- danjoc 9y agoFriendly reminder, every time this happens... https://github.com/npm/npm/pull/4016 https://github.com/npm/npm/pull/4016 "However, this is just a piece of an overall solution, and it brings with it a lot of the baggage that comes along whenever GnuPG or PGP get involved. Without a web of trust (sigh), a PKI (ugh), or some other mechanism to tie identities to trust metrics, this is essentially a complicated, very expensive, and fragile version of the shasum check npm already has." I really like how the NPM simultaneously insults two legends in crypto and does _nothing_ to protect the node ecosystem, deferring to "better solutions" that don't exist and will never exist. They've done literally nothing. https://github.com/node-forward/discussions/issues/29 https://github.com/node-forward/discussions/issues/29 Last discussion was > 1 year ago. They simply do not care. Security isn't even an afterthought.
- stu_k 9y agoI'm confused, how would the above help with a typosquatting package? The issue here is that `crossenv` is malicious, and `cross-env` isn't. The signatures would all be ok in both cases.
- KirinDave 9y agoIt wouldn't. People look for any opportunity they can muster to browbeat the node community. Probably because they're jealous of its outsized success.
- danjoc 9y agoThe signature might validate, but at the point you go to Kent C Dobbs to verify he controls the key, the ruse is uncovered.
- koolba 9y agoAnd nobody but the most tinfoily of us is going to do that. So short of a web of trust or delegation, you get nothing more than a checksum.
- 9y ago
- iamakulov 9y agoFor everyone, here’s a one-liner to check your dependency tree: npm ls | grep -E "babelcli|crossenv|cross-env.js|d3.js|fabric-js|ffmepg|gruntcli|http-proxy.js|jquery.js|mariadb|mongose|mssql.js|mssql-node|mysqljs|nodecaffe|nodefabric|node-fabric|nodeffmpeg|nodemailer-js|nodemailer.js|nodemssql|node-opencv|node-opensl|node-openssl|noderequest|nodesass|nodesqlite|node-sqlite|node-tkinter|opencv.js|openssl.js|proxy.js|shadowsock|smb|sqlite.js|sqliter|sqlserver|tkinter" (More details: https://iamakulov.com/notes/npm-malicious-packages/ https://iamakulov.com/notes/npm-malicious-packages/)
- ThrustVectoring 9y agoThere's a minor regex error in the one-liner: not escaping the dot, which matches any character. Fortunately that won't cause any false negatives, and will only incorrectly match weird things like fabric9js Fixed: npm ls | grep -E "babelcli|crossenv|cross-env\.js|d3\.js|fabric-js|ffmepg|gruntcli|http-proxy\.js|jquery.js|mariadb|mongose|mssql\.js|mssql-node|mysqljs|nodecaffe|nodefabric|node-fabric|nodeffmpeg|nodemailer-js|nodemailer\.js|nodemssql|node-opencv|node-opensl|node-openssl|noderequest|nodesass|nodesqlite|node-sqlite|node-tkinter|opencv\.js|openssl\.js|proxy\.js|shadowsock|smb|sqlite\.js|sqliter|sqlserver|tkinter"
- hiendv 9y agoI would add a "@" npm ls | grep -E '(babelcli|crossenv|cross-env\.js|d3\.js|fabric-js|ffmepg|gruntcli|http-proxy\.js|jquery\.js|mariadb|mongose|mssql\.js|nodecaffe|nodefabric|node-fabric|nodeffmpeg|nodemailer-js|nodemailer\.js|nodemssql|node-opencv|node-opensl|node-openssl|noderequest|nodesass|nodesqlite|node-sqlite|node-tkinter|opencv\.js|openssl\.js|proxy\.js|shadowsock|smb|sqlite\.js|sqliter|sqlserver|tkinter)@'
- pintxo 9y agoOr to check all your npm modules within a directory: grep -r -i --include package.json -E '(babelcli|crossenv|cross-env\.js|d3\.js|fabric-js|ffmepg|gruntcli|http-proxy\.js|jquery\.js|mariadb|mongose|mssql\.js|nodecaffe|nodefabric|node-fabric|nodeffmpeg|nodemailer-js|nodemailer\.js|nodemssql|node-opencv|node-opensl|node-openssl|noderequest|nodesass|nodesqlite|node-sqlite|node-tkinter|opencv\.js|openssl\.js|proxy\.js|shadowsock|smb|sqlite\.js|sqliter|sqlserver|tkinter)@'
- mjs 9y agoGoogle cache suggests no downloads, fortunately: https://webcache.googleusercontent.com/search?q=cache:zAzfBZIg0vYJ:https://www.npmjs.com/package/crossenv+&cd=1&hl=en&ct=clnk&gl=uk https://webcache.googleusercontent.com/search?q=cache:zAzfBZ...
- iamakulov 9y agoIt’s of 19th July :–(
- smaili 9y agoLooks like it's being logged to npm.hacktask.net/log Couldn't the developer have at least chosen a less suspicious domain name? :)
- JCharante 9y agoTo be fair hacktask was their username, so they're being consistent.
- albertgoeswoof 9y agoI wonder why they didn't obfuscate the code a bit more, they could have even positioned it as a reference package that helps resolve typos. Would be interesting to know how many systems have potentially been hit by this, and if any leaked production credentials. I think it's unlikely to yield a lot of useful results due to then drag net nature of the project. A targeted attack might make more sense (e.g. On an open source library, targeting specific developers)
- xxxdarrenxxx 9y agoThis is not unexpected if u take into account behind all the code are still humans. Everyone can share everything for free, safe and sound in a happy world. Didn't happen ever in the "real world", won't happen here. It's idealistic bias. I'm sure many things have been written on this, but this is essentially an issue rooted in human behaviour. It always comes down to having a or multiple arbiter(s) to maintain a standard. The issue with this in these type off ecosystems is that it's simply too big and too dynamic unless devs and the curators are on common terms release wise. By now you basically are threading being an organisation potentially elevating privileges with just a small portion off devs to realistically deal with the scale off things. In this centralized state it can swing the other way, mainting heavy arbiting and release standards (Apple for example), creating a potential more stable and secure but closed system.
- fpgaminer 9y agoIs there an api to query recent NPM packages, as well as get a full list of packages? It'd be interesting to write a tool that monitors as packages are added to npm, compare them against the existing list, and check for potential typo-squatting. Like, remove dashes, check Levenshtein distance, etc. I mean, NPM themselves should be doing that but ... since they aren't, might as well do it for them, ya?
- deleted 9y ago[deleted]
- water42 9y agohttps://skimdb.npmjs.com/registry/_design/scratch/_view/byField https://skimdb.npmjs.com/registry/_design/scratch/_view/byFi... looks like there is an api
- thangngoc89 9y agonpm maintains a mirror of CouchDB here https://skimdb.npmjs.com https://skimdb.npmjs.com. You can use any tools that understand CouchDB to get all of those information
- fiatjaf 9y agoThis is issue is not so hard to deal with. 1. For every big, important package, you can probably count on number of downloads/stars a library has to attest its trustworthiness. 2. For small packages, you should always look at the code directly. Search npm, see the GitHub repository link, click, read the source to see if it more-or-less does what you want. I think a lot of people do this already. 3. Typosquatting is still the only unsolved problem, but an addition to the npm CLI that checks if there are packages with similar names when you're downloading and alerts you -- maybe even suggesting the package that has much more downloads/stars -- should solve that.
- Klathmon 9y agoOr package authors should start using scoped packages. Instead of publishing as cross-env you publish as @guy/cross-env That makes typosquatting harder, and can help give users some ideas of packages which are by the same authors. NPM could help by allowing packages to be published both to the "global namespace" AND as a scoped package automatically. (In other words, always allow accessing any global package by it's scoped name)
- fiatjaf 9y agoYes, I like that idea. I would rather have some GitHub integration in place, so I could `npm install github.com/someone/somepackage`, like Golang forces us to do, for example. I don't do that for all packages automatically nowadays because there is this bizarre culture of people publishing different things to npm and GitHub. To npm they send only "built" files from ES7 to ES5-compatible mode, while to GitHub go only the unbuilt sources which will not run anywhere. A solution to that would be for an automatic builder to be run on every `git push`. A third-party service, somehow, someone, somewhere. Travis CI, maybe? I'm waiting for someone to have an insight and solve this problem in these lines.
- johncomposed 9y agoNpm has had github integration for a while now (and straight git integration). Depending on how they setup things, a repo with a good postinstall script will build once it gets pulled so you'll have ES5 compatible files in your node_modules by the time you are running your application. Not that that's an ideal system, but it's an option for some packages.
- kentor 9y agoif you have yarn run yarn why crossenv to see if you have it in your dependency tree
- hitgeek 9y agothis is really bad for npm. I think they hold some responsibility in allowing an obviously malicious package to impersonate popular packages. I would like to see an official response with action plan. I recall this attack vector being discussed in the aftermath of left-pad. an unfortunate irony is that the current post on the npm blog is "Securing the npm registry" from 12hrs ago.
- Spivak 9y agoNot really much they can do other than take it down and maybe 'protect' some popular packages from typo squatting by reserving some common misspellings. They're a public repository where users upload arbitrary code. The trust relationship really isn't there. You trust NPM to be secure and serve exactly the code that the author published unmodified. You trust the author to not act maliciously. Nothing you can really do if a user voluntaitally installs leet-virus.
- lathiat 9y agoJust yesterday there was a thread about how the chrome plugin "user agent switcher" sends your entire browsing history externally. And it's still published. The problem is not unique to the npm ecosystem, the main problem here is "web of trust" whether through GPG or even just things like 'download counts', etc.
- tim333 9y agoAlso there are at least three chrome extensions in the store called "user agent switcher" which confuses matters. From useragentswitcher.org, google.com and toolshack.com
- hatsunearu 9y agoI'm new to the JS ecosystem--who is Oscar and who is Kent? Also who's hacktask?
- micaksica 9y agoOscar is a dev, Kent is the maintainer of "cross-env", a popular package. hacktask is an unknown malicious module uploader that was harvesting credentials.
- Veedrac 9y agoAll of this seems fixable by just providing decent UI protections. Error when typo-squat domains near-alias more popular packages; force them to pass a flag to override. Is there a reason this isn't done, or has it just not been allocated the time to build it?
- diimdeep 9y agohttp://dev.hacktask.org http://dev.hacktask.org is look like SAAS for XSS attacks (free registration, use google translate) screenshots: https://imgur.com/a/BGyME https://imgur.com/a/BGyME I found it at https://github.com/leanone/v1/blob/2980984c003d8016ac48d3f87ab7f148781fe5f5/application/controllers/test.php#L16 https://github.com/leanone/v1/blob/2980984c003d8016ac48d3f87... redirects to https://dev.hacktask.org/p/58ad07f57e25ce001b19f776/ https://dev.hacktask.org/p/58ad07f57e25ce001b19f776/ I created account (use google translate) and played with it, use this link to show me who you are https://dev.hacktask.org/client/59815d7f5ff1a2001b9ee398/ https://dev.hacktask.org/client/59815d7f5ff1a2001b9ee398/
- deleted 9y ago[deleted]
- pneiman 9y agoThanks for the heads up
- reaktivo 9y agoAnother possible solution for this problem would be that for each module's `package.json` a list of node APIs that a module opts-out, like http, access to env variables, fs, etc. This would need to apply to the package itself and any dependencies it requires.
- krallja 9y agoThis package was running a Bash script at install time. Perhaps that's the permission which should be denied.
- partycoder 9y agonpx makes it even easier. Make a typo while running a command and you are done.
- unkown-unknowns 9y agoI wonder how it was detected. Also someone ITT said something about if they'd squatted the dependencies it wouldn't have been seen or something? Can't find back to that comment.
- RX14 9y agoIn Crystal, we've decided that the dependency manager shards will have no centralised package repository, which we hope will solve problems like this. It makes forking shards very easy, it completely avoids name squatting, and it should help prevent typo squatting like this. We also don't want shards to become yet another system package manager, used for installing executables to your PATH. Shards should never be run as root, unlike npm and pip.
- lsiebert 9y agofor every node package, see what node packages are 3 or less levenshtein distance away when it's uploaded, and go through all existing packages. Add an optional flag that will, if you try to install a package that has a package within that edit distance that is an order of magnitude more popular, give you warning and skip that package, an optional flag that errors, and a way to force it for a specific package. In the future, make the first optional flag the default, so people get warnings with instructions to override. Allow white listing of particular packages that may be problematic, and expect a shared white list Then, a year later after repeated warnings of the coming nodepocalypse, make the second optional flag the default, so if you haven't white listed or explicitly forced installing such a package, it will fail. You will, of course break production for a few people who just didn't listen. Alternatively, instead of edit distance, allow users to report problematic packages and do a similar thing. Do not provide a explicit award to users who report, so nobody would create fake malware just to report it. In both cases, either implicitly or explicitly you are using the wisdom of the crowd to figure out the bad packages.
- krapp 9y agoIs there likely to be a good reason for one package name to be two or three character transforms away from another? Maybe have all packages be scoped under a namespace, and then globally require a minimal uniqueness for the package name itself.
- Mobizone_Ng 9y agoTwitter Introduces Turn Off Notification From The Strangers. — [SEE HOW]..http://mobizone.ng/twitter-introduces-turn-off-notification-strangers/ http://mobizone.ng/twitter-introduces-turn-off-notification-...
- dankent 9y agoI've knocked together a quick tool that might help to spot such typosquatting: https://www.npmjs.com/package/check-typosquatters https://www.npmjs.com/package/check-typosquatters (It's the first time I've published anything to npm so let me know if I have done anything wrong...) It uses the list of package names from the all-the-package-names package and returns the 10 packages with the most similar names to the supplied parameter (using Levenshtein distance) It also displays their rank based on dependent packages to give an idea of how they compare in usage. I'm sure there are improvements that could be made - PRs welcome on the github repository.