5 ms·
Backdoor injected to NPM express-cookies package
Remote code injection vulnerability wild in public npm package, plausible-sounding 'express-cookies' and its dependency 'getcookies'. >10K downloads during April.
Vulnerable code: https://npm.runkit.com/getcookies/test/harness.js?t=1525249320108
https://www.npmjs.com/package/express-cookies
- chrbp 8y agoI am curious to know whether you reported it to npm upon your findings. npm questioned me for who to credit on this matter, and they would like to know who the original finder was.
- Aspyre 8y agoAm I the only one that's only reading the comments after seeing the first two words of the title?
- fuckyouzilla 8y agoProofs?
- jononor 8y agoNo links to git repo in the packages, big warning sign.
- seanwhitsell 8y agoSuspiciously good looking profile pic for the developer too; https://www.google.com/search?tbs=sbi:AMhZZite6RvKwDFjIobMX-kFh9uYB5vV1g-iN63JdRUO-6A65UJx3I2bridaMp8pyyG5-RvL77Kcv9Kh692YTw_1Zmpa-l7oEbi39X2NDGE7aQQ0rRKYBmTmOAeeqpsNkusNH8LzWMCFr756Dn-qlbJgaWjEfyj1x_1eUJDvUCFv4f9dDapoKOc_1rRG06pBxaaxcMW14Rrgccz4PNTYmjxyt1EpkS8oVSY8EYaOqbDJoVX7zCAsPWCSWH_1hoPjF0h2ieBiGaslHh4uXo-ySbVxhqVjLZM2JeGw9HaRhHfpQAzBVqGmvYReRdE2IVQvAinapYZQokhM_1TprPgk52_1SSGoatnctN77pzPg https://www.google.com/search?tbs=sbi:AMhZZite6RvKwDFjIobMX-...
- mindcrash 8y agoBecause it's a crop from a stock photo with a male model (in fact, see the first image result on the page).
- cathhhhji 8y agoThere is no reason to use "express-cookies" when "cookie-parser" exists.
- hinkley 8y agoExpress just ejected a bunch of its functionality into “express-“ modules.
- deleted 8y ago[deleted]
- ekke 8y agoAnd NPM took it down quickly, whew.
- lucfranken 8y agodid you report it to NPM?
- chrbp 8y agoI don't know how many reported it to npm, but when I initially saw the post on HN, I took the steps to report the packages. I don't know who to credit on this, and neither does npm but OP seems to be the source of these findings, although it would baffle me if they didn't report it to npm.
- ekke 8y agoSure, and at least few more people :)
- jononor 8y agoCan someone explain how the injection itself works? I assume it's the require doing the work, but its not so clear how that loads externally instead of from a path in filesystem?
- dylz 8y agoIt appears to be middleware that looks at headers, and if a certain condition is met, it'll basically execute https://nodejs.org/api/vm.html#vm_vm_runinthiscontext_code_options https://nodejs.org/api/vm.html#vm_vm_runinthiscontext_code_o... against whatever the header has.
- ekke 8y agoNPM guys explain it in the blog today: https://news.ycombinator.com/item?id=16975025 https://news.ycombinator.com/item?id=16975025
- jononor 8y agoCorrected URL to blogpost is: https://blog.npmjs.org/post/173526807575/reported-malicious-module-getcookies https://blog.npmjs.org/post/173526807575/reported-malicious-...