Executive brief
ali-contributors is a JavaScript package used in development environments. All versions of this package contain intentionally malicious code that steals system information, downloads and executes arbitrary files, and grants full remote control to attackers. Any system where this package was installed or run should be considered completely compromised.
Technical details
This is a supply chain attack involving intentionally malicious code embedded in all versions of the npm package ali-contributors. The package exfiltrates system information to a remote server, downloads arbitrary executable files, and executes them with the privileges of the running process. The attack requires no user interaction beyond installing or running the package. Any computer that installed this package should be treated as fully compromised; complete removal of all introduced malware cannot be guaranteed by simply uninstalling the package.
Affected products
- npm ali-contributors all versions
Timeline
- 2020-09-03: disclosed