Junglewise Threat Intelligence

CVE-2016-10634: scalajs-standalone-bin insecure HTTP resource download

CVE-2016-10634 · Severity: info · Published 2019-02-18

Vendors: npm.

Executive brief

scalajs-standalone-bin is a JavaScript build tool that downloads executable resources over an unencrypted HTTP connection instead of HTTPS. An attacker with network access (such as on a public WiFi network or a compromised ISP) can intercept these downloads and inject malicious code, leading to arbitrary code execution on the developer's machine during installation.

Technical details

The vulnerability is a missing encryption issue (CWE-311) where scalajs-standalone-bin downloads an executable file over HTTP instead of HTTPS. The attack requires a privileged network position (man-in-the-middle capability) to intercept and modify the download before installation. Any attacker on the same network or with ISP-level access can perform this interception. The impact is remote code execution with the privileges of the user installing the package. No patch has been released; the only mitigation is to avoid the package entirely or install only on private, trusted networks.

Affected products

  • scalajs scalajs-standalone-bin 0.4.3 and earlier

Timeline

  • 2019-02-18: disclosed
  • other: CVE-2016-10634 assigned (publication lag suggests earlier discovery)