3 ms·
I was working on a PR for a Node project when I read about this. My changes added some new dependencies and I wanted to make sure I hadn't pulled in any package
by jake-low 8y ago
I was working on a PR for a Node project when I read about this. My changes added some new dependencies and I wanted to make sure I hadn't pulled in any packages that were updated after this incident began (since the authors of those packages might have had their credentials compromised and used to push malicious updates to their packages).
I wrote a script to extract all of my changed dependencies from package-lock.json and retrieve the publication date of the resolved version from registry.npmjs.org. It's hacky but here's the steps:
First run this pipeline. You can change the first two lines if you're interested in the whole package-lock.json; I was just interested in my changes.
git diff master -- package-lock.json \
| grep '+\s*"resolved":' \
| awk '$2 == "\"resolved\":" {print $3}' \
| cut -d '"' -f2 \
| perl -pe "s/\/-\/(?:\\S+-)((?:[0-9]+)(?:\\.[0-9]+)+\\S+)\\.tgz/ \1/" \
> dep-urls-and-versions.txt
You now have a file which contains on each line a URL, then a space, then a version string. I ran this python script on the file.
import requests
with open("dep-urls-and-versions.txt", "r") as f:
for line in f.readlines():
url, version = line.strip().split(" ")
res = requests.get(url)
body = res.json()
print(body["time"][version], body["name"])
Run it as `python script.py | sort` and you'll get the most recently published packages in your package-lock.json. Just check that the last (bottom-most) timestamp is older than 2018-07-12 10:25 UTC when the first compromised package was published.
Hope that helps someone.