3 ms·
There is an explanation in the article: > it modifies package.json based on the current environment's npm configuration, injects [malicious] setup_bun.js and b
by merelysounds 11mo ago
There is an explanation in the article:
> it modifies package.json based on the current environment's npm configuration, injects [malicious] setup_bun.js and bun_environment.js, repacks the component, and executes npm publish using stolen tokens, thereby achieving worm-like propagation.
This is the second time an attack like this happens, others may be familiar with this context already and share fewer details and explanations than usual.
Previous discussions: https://news.ycombinator.com/item?id=45260741 https://news.ycombinator.com/item?id=45260741
- vintagedave 11mo agoThanks. I saw that sentence but somehow didn't parse it. Need a coffee :/
- tasuki 11mo agoI don't get this explanation. How does it force you to run the infection code? Yes, if you depend on an infected package, sure. But then I'd expect not just a list, but a graph outlining which package infected which other package. Overall I don't understand this at all.
- merelysounds 11mo agoLook at the diff in the article, it shows the “inject” part: the malicious file is added to the “preinstall” attribute in the package.json.
- tasuki 11mo agoI still don't get it. Like, I understand that if you apply the diff you get infected. But... why would you apply the diff? How would you trick me to apply that diff to my package?
- theodorejb 11mo agoSomeone could be tricked into giving their npm credentials to the attacker (e.g. via a phishing email), and then the attacker publishes new versions of their packages with the malicious diff. Then when the infected packages are installed, npm runs the malicious preinstall script which harvests secrets from the new machine, and if these include an npm token the worm can see which packages it has access to publish, and infect them too to continue spreading.