Executive brief
scalajs-standalone-bin is a JavaScript build tool that downloads executable resources over an unencrypted HTTP connection instead of HTTPS. An attacker with network access (such as on a public WiFi network or a compromised ISP) can intercept these downloads and inject malicious code, leading to arbitrary code execution on the developer's machine during installation.
Technical details
The vulnerability is a missing encryption issue (CWE-311) where scalajs-standalone-bin downloads an executable file over HTTP instead of HTTPS. The attack requires a privileged network position (man-in-the-middle capability) to intercept and modify the download before installation. Any attacker on the same network or with ISP-level access can perform this interception. The impact is remote code execution with the privileges of the user installing the package. No patch has been released; the only mitigation is to avoid the package entirely or install only on private, trusted networks.
Affected products
- scalajs scalajs-standalone-bin 0.4.3 and earlier
Timeline
- 2019-02-18: disclosed
- other: CVE-2016-10634 assigned (publication lag suggests earlier discovery)