Junglewise Threat Intelligence

ali-contributor malicious package code execution

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

ali-contributor is a Node.js package that contained malicious code designed to steal system information and execute arbitrary commands on infected machines. Any system with this package installed should be considered fully compromised, with all credentials and secrets rotated immediately from a clean system. Complete removal cannot be guaranteed since the malicious code may have given external attackers full system control.

Technical details

The ali-contributor npm package contains intentionally malicious code (CWE-506: Embedded Malicious Code) that exfiltrates system information to a remote server and downloads arbitrary files for execution. The attack vector is network-based with no authentication required; exploitation occurs automatically upon package installation or execution. An attacker gains remote code execution and full system compromise. All versions are affected; the package should be removed immediately, though complete remediation requires reimaging or professional incident response, as removal alone may not eliminate all backdoors or persistence mechanisms left by the attacker.

Affected products

  • ali-contributor ali-contributor all versions

Timeline

  • 2020-09-03: disclosed

References