Junglewise Threat Intelligence

asycn typosquatting package with user tracking

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

The asycn npm package is a malicious package that exploits a common typo in the name of a legitimate, widely-used library. When installed, it silently collects and transmits information about the developer's environment (package name, Node version, sudo status) to a remote server. This represents a supply-chain attack that could expose development infrastructure details and enable targeted follow-up attacks.

Technical details

The asycn package is a typosquatting attack targeting developers who mistype the name of the popular "async" library. The package does not provide legitimate functionality; instead, it performs reconnaissance by gathering system metadata (downloaded package name, intended package name, Node.js version, and whether the process runs with elevated privileges) and exfiltrating it to an attacker-controlled server. The attack requires no user interaction beyond the installation step and affects all versions. No further code execution or system compromise occurs beyond the telemetry collection, but the metadata leak enables attackers to profile victims for subsequent targeted attacks.

Affected products

  • npm asycn all

Timeline

  • 2020-09-02: disclosed

References