Junglewise Threat Intelligence

antd-cloud malicious package with arbitrary code execution

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The antd-cloud npm package contains malicious code that exfiltrates system information to remote servers and downloads and executes arbitrary files. Any system running this package should be considered fully compromised, with all credentials and keys rotated immediately from a different machine. Complete removal of the package may not eliminate all malicious software that was installed.

Technical details

The antd-cloud npm package contains embedded malicious code (CWE-506: Embedded Malicious Code) that is automatically executed upon installation or package initialization. The malware collects and exfiltrates system information to attacker-controlled remote servers, and has the capability to download and execute arbitrary files with the privileges of the node process. This is a supply-chain attack vector requiring no user interaction beyond installing the package via npm. Because the malicious code gains full control of the runtime environment, removal of the package alone may not eliminate all compromises introduced by the installation.

Affected products

  • npm antd-cloud all versions

Timeline

  • 2020-09-03: disclosed
  • 2020-08-31: advisory

References