5 ms·
NPM foils plot that was only possible due to ridiculous house of cards built by NPM. I notice that the NPM blog post also fails to mention that it was actually
by MoronInAHurry 7y ago
NPM foils plot that was only possible due to ridiculous house of cards built by NPM.
I notice that the NPM blog post also fails to mention that it was actually successful and resulted in about 1 million KMD (current value ~$1.7M) being stolen. The Komodo blog post contains that information: https://komodoplatform.com/update-agama-vulnerability/ https://komodoplatform.com/update-agama-vulnerability/
Even worse, they had also successfully stolen about 9 times more than that. The only reason it was prevented was because the seeds were being sent to a public server, and Komodo was able to access and use them to "steal" the 8 million coins (and 96 BTC) from those wallets before the attacker did.
This was a successful $10M+ theft that NPM is somehow trying to spin into a positive.
- spyder 7y agoHm... to claim the coins they saved, you have to receive and send a small transaction from the compromised wallet to verify ownership. But how do they make sure that it's not claimed by the hackers who may have the seed of these wallets? The only thing they say is that they don't send it if there is multiply claims (probably one from hacker and one from real owner).
- aasasd 7y agoI went straight to the comments on this HN submission because I knew NPM couldn't just be good guys.
- matthewbauer 7y agoI don’t think it’s fair to single npm out here. The truth is any package manager that lets anyone publish package updates is vulnerable to this type of attack.
- matthewbauer 7y agoSemver probably makes the problem worse though.
- wheelerwj 7y agohow?
- matthewbauer 7y agoDependency ranges mean package updates happen automatically. So a minor release could contain malicious code without anyone noticing. I still think semver is worthwhile even if it a little bit more vulnerable to this kind of attack.
- solidasparagus 7y agoYeah, but a dependency attack is a rarer issue than out-of-date dependencies that contain known security vulnerabilities.
- pdpi 7y agoBecause if you don't consider SemVer as part of your threat model, you'll specify "v1.2.3 or above" instead of "v1.2.3".
- SanchoPanda 7y agoNPM isn't being singled out as part of a hypothetical risk analysis, this is about an attack that actually happened via NPM.
- dtech 7y agonpm encourages an auto-upgrading versioning scheme: take version x or higher. It's great for keeping dependencies up-to-date, but this makes it immensely vulnerable to the kind of malware injection, as publishing a library version with payload will immediately propagate throughout the ecosystem. In most other version managers (e.g. maven) every library and application specifies a hard-coded version, which requires users to manually upgrade, giving a window were a malicious version can be detected before it affects anyone.
- cortesoft 7y agoIn this case, though, someone explicitly changed the included version to the malicious one.
- nullandvoid 7y agoFor a security critical app not locking down the dependencies to audited versions seems very dangerous indeed and I believe there is some blame to be had there
- matthewbauer 7y agoYou’re still vulnerable if you lock down dependencies during the period the malicious code is wild though. You have to actually audit your locked dependencies to consider yourself safe.
- undecisive 7y agoIsn't that expecting the car to be invented before the wheel? From what I've seen, quite a few of these have been targetted attacks - the assailants have targetted specific variables that existed in a specific codebase that they knew imports their module. Of course, if you've only just started writing that codebase, your dependencies have no way of knowing where you're storing private keys (short of somehow scanning the object space for variable names like "private_key") But yes, in theory I would love for any *-sensitive code to go through a thorough audit after every dependency update before a version gets released in the wild. I'm guessing that next-to-nobody has the resources for that kind of an effort though.
- GordonS 7y agoNPM has, specifically and deliberately, played down the successful theft here, making out that they completely foiled it. If they hadn't done such a scummy, corporate spin job on this, I'd be inclined to agree with you - but they did.
- wheelerwj 7y agoagreed for the most part. "Foiled" is pretty much the wrong word here. Maybe "Detected and halted further loss..."
- gcb0 7y agoThat's wrong too. What they did was to allow komodo to, vigilante style, outright steal the coins, and hold them hostage until you entertain them with proof of ownership/identity and whatever other ridiculous requirements they come up with. But it's npm and kleptocurrency. Nothing of value lost.
- Chazprime 7y agoI’m honestly amazed this hasn’t happened more often; it’s ridiculous that a developer has to install thousands of lines of code to create a simple “hello world” website.
- aasasd 7y agoGuess someone slipped you a wrong thing instead of Node, because for me, about five lines and zero dependencies work fine.
- tedunangst 7y agoProbably confused node and react.
- saxonww 7y agoMaybe the post has been edited, but just now it reads '"hello-world" website'. When I search for "create a website with node.js" the top results all talk about using Express.js. If I `npm init` and then `npm install express` as suggested, the result is 50 packages installed containing 21707 lines of javascript. edit: trying to show what people are steered towards when looking up how to do this themselves.
- dane-pgp 7y agoReact is a better example: https://twitter.com/dylanbeattie/status/1098204272653676544?lang=en https://twitter.com/dylanbeattie/status/1098204272653676544?... "Before you even open a text editor, your project contains 1.5 million lines of code. Most of it contributed by volunteers and enthusiasts. No formal review or release process."
- cameronbrown 7y agoA terrible argument given that React is a Facebook project, initially built and shipped by only Facebook employees, not random volunteers.