Executive brief
The aysnc package on npm was a typosquatted imposter of a legitimate library, designed to trick developers into installing it by mistake. Once installed, it silently collected and transmitted information about the user's system to remote servers, including system configuration and whether the install ran with elevated privileges, though no additional system compromise occurred.
Technical details
This is a supply chain attack via typosquatting—the package mimicked a legitimate library's name to exploit developer mistakes during installation. Upon execution, the malicious code collected metadata (installed package name, intended package name, Node version, and sudo privilege status) and exfiltrated it to a remote server without user knowledge or consent. The attack vector is social engineering / installation-time injection; no authentication, network compromise, or user interaction beyond the initial install is required. An attacker gains environmental reconnaissance and visibility into deployment infrastructure. The vulnerability is classified under CWE-506 (Web Application Logic Errors / Supply Chain). No patch is applicable—the only remediation is to remove the package entirely and reinstall the correct, legitimate package.
Affected products
- npm aysnc all versions
Timeline
- 2020-09-02: disclosed