11 ms·
PSA: Please be cautious because this is an excellent opportunity for taking over packages and injecting malware by malicious people. Example: https://www.npmjs
by racbart 9y ago
PSA: Please be cautious because this is an excellent opportunity for taking over packages and injecting malware by malicious people.
Example: https://www.npmjs.com/package/duplexer3 https://www.npmjs.com/package/duplexer3 which has 4M monthly downloads just reappeared, published by a fresh npm user. They published another two versions since then, so it's possible they've initially republished unchanged package, but now are messing with the code.
Previously the package belonged to someone else: https://webcache.googleusercontent.com/search?q=cache:oDbrgPbT5m0J:https://www.npmjs.com/package/duplexer3 https://webcache.googleusercontent.com/search?q=cache:oDbrgP...
I'm not saying it's a malicious attempt, but it might be and it very much looks like. Be cautious as you might don't notice if some packages your code is dependent on were republished with a malicious code. It might take some time for NPM to sort this out and restore original packages.
- weinzierl 9y agoDetailed description what you could do with a malicious npm package is currently on he front page: "Harvesting credit card numbers and passwords from websites" https://news.ycombinator.com/item?id=16084575 https://news.ycombinator.com/item?id=16084575
- marpstar 9y agoam I the only one who thinks this could be more than a coincidence?
- amself 9y agoI find it hard to believe, but never say never, of course.
- ohiovr 9y agoI didn't think of it. But it is a coincidence, Good one.
- bubble_boi 9y agoHey, I wrote that article :) - yes it was pure coincidence, I just decided with all the security stuff going on this week (Spectre/Meltdown, I hadn't heard about the npm stuff) I'd write and article about it.
- swang 9y agodidn't npm make some changes where a published package name cannot be republished, at least not without npm intervention?
- incogitomode 9y agoI just tested, and it definitely looks like a troll / hack. > duplexer3@1.0.1 install /Users/foo/Code/foo/node_modules/duplexer3 > echo "To every thing there is a season, and a time to every purpose under the heaven: A time to be born, and a time to die; a time to plant, and a time to pluck up that which is planted; A time to kill, and a time to heal; a time to break down, and a time to build up; A time to weep, and a time to laugh; a time to mourn, and a time to dance; A time to cast away stones, and a time to gather stones together; a time to embrace, and a time to refrain from embracing; A time to get, and a time to lose; a time to keep, and a time to cast away; A time to rend, and a time to sew; a time to keep silence, and a time to speak; A time to love, and a time to hate; a time of war, and a time of peace. A time to make use of duplexer3, and a time to be without duplexer3." To every thing there is a season, and a time to every purpose under the heaven: A time to be born, and a time to die; a time to plant, and a time to pluck up that which is planted; A time to kill, and a time to heal; a time to break down, and a time to build up; A time to weep, and a time to laugh; a time to mourn, and a time to dance; A time to cast away stones, and a time to gather stones together; a time to embrace, and a time to refrain from embracing; A time to get, and a time to lose; a time to keep, and a time to cast away; A time to rend, and a time to sew; a time to keep silence, and a time to speak; A time to love, and a time to hate; a time of war, and a time of peace. A time to make use of duplexer3, and a time to be without duplexer3.
- pul 9y agoThey're referencing the Bible: https://www.biblegateway.com/passage/?search=Ecclesiastes+3&version=KJV https://www.biblegateway.com/passage/?search=Ecclesiastes+3&...
- snomad 9y agoThe Byrds, Turn! Turn! Turn!
- rubyn00bie 9y agoI’m pretty sure they’re referencing the Byrds song and not the Bible directly: https://m.youtube.com/watch?feature=youtu.be&v=pKP4cfU28vM https://m.youtube.com/watch?feature=youtu.be&v=pKP4cfU28vM
- no29 9y agomaybe it's time to push for adding signed packages to npm long discussion here: https://github.com/node-forward/discussions/issues/29 https://github.com/node-forward/discussions/issues/29
- edejong 9y agoI am very surprised that a package manager of this calibre and impact abstains from best practices when it comes to authentication through code-signing. Other package managers are miles ahead of NPM. For example, Nix, which uses immutability and hashing to always produce the same artifact, regardless of changes of the sources.
- djsumdog 9y agoSo I know rpms and debs are signed, as I've setup repos for both. Docker repositories require a valid SSL key (or you have to manually allow untrusted repos). But do Python packages and Ruby gems have signature verification? How does pypy/pip and gem deal with validating a package is what it claims to be?
- viraptor 9y agoTraditional python packages support GPG signing: https://pypi.python.org/security https://pypi.python.org/security There's new experimental signing in wheels: https://wheel.readthedocs.io/en/stable/#automatically-sign-wheel-files https://wheel.readthedocs.io/en/stable/#automatically-sign-w... and the signing defined in PEP: https://www.python.org/dev/peps/pep-0427/#signed-wheel-files https://www.python.org/dev/peps/pep-0427/#signed-wheel-files
- cpburns2009 9y agoPyPI (which is what Pip uses) at the very least does not require authors to sign their packages. I can't say whether it supports signing though.
- ek750 9y agoRuby gems can be signed but the percentage of gems authors taking advantage of that is low. At least we’ve got most people using https to transfer gems now!
- maxander 9y agoAnd all this is happening just as after the public release of a serious exploit which allows malicious code to do all sorts of nefarious things when it is somehow installed on the target machine. Hmm. Given that there's hints, at least, that the problems were caused by some particular developer's actions, I wonder about the security model for package-managed platforms altogether now. If I were a big cybercrime ring, the first thing I'd do would be, get a bunch of thugs together and knock on the front door of a developer of a widely-used package; "help us launch [the sort of attack we're seeing here] or we'll [be very upset with you] with this wrench." Is there a valid defense for a platform whose security relies on the unanimous cooperation of a widely-scattered developer base?
- tetha 9y ago> Is there a valid defense for a platform whose security relies on the unanimous cooperation of a widely-scattered developer base? The defense is staged deployment and active users. This obviously depends on the blutness of the malicious code. If I may assume easily noticed effects of the malicious code: A dev at our place - using java with maven - would update the library, his workstation would get owned. This could have impacts, but if we notice, we'd wipe that workstation, re-image from backup and get in contact with sonatype to kill that version. This version would never touch staging, the last step before prod. If we don't notice on the workstation, there's a good chance we or our IDS would notice trouble either on our testing servers or our staging servers, since especially staging is similar to prod and subject to load tests similar to prod load. Once we're there, it's back to bug reports with the library and contact with sonatype to handle that version. If we can't notice the malicious code at all until due to really really smart activation mechanisms... well then we're in NSA conspiracy land again.
- paulryanrogers 9y agoSounds like good hygiene, though it seems burdensome if everyone must do it or seriously risk infection. Ideally there would be at least minimal sanity checks and a formal process before a package can be claimed by someone else.
- 9y ago
- csdreamer7 9y agoHow does RubyGems handle a package being removed and replaced by a different (and maybe malicious) actor? Not allow a package to be deleted? Block the package name from being claimed by someone else?
- eric_h 9y agoFrom http://help.rubygems.org/kb/gemcutter/removing-a-published-rubygem http://help.rubygems.org/kb/gemcutter/removing-a-published-r...: > Once you've yanked all versions of a gem, anyone can push onto that same gem namespace and effectively take it over. This way, we kind of automate the process of taking over old gem namespaces.
- shostack 9y agoSo basically--gem bundler beware?
- csdreamer7 9y agoThank you Eric.
- Footkerchief 9y agoThere are also people requesting that this be changed: https://github.com/rubygems/rubygems.org/issues/1226 https://github.com/rubygems/rubygems.org/issues/1226
- wybiral 9y agoNPM doesn't make the package names unavailable after removal??? EDIT: That would be a massive security problem!
- wybiral 9y agoWait, they both say username = floatdrop [1] for me. What did they say for you? [1] https://twitter.com/floatdrop https://twitter.com/floatdrop
- Pyrodogg 9y agoI'm surprised there wasn't a global lock-down on new package registrations (or at least with the known names of lost packages) while they were working to restore them.
- codetoliveby 9y agoShit. That's a good point, I downloaded the Heroku CALI during the attack and it uses duplexer3. I got a weird message that seemed "off" during postinstall.