Executive brief
slimerjs-edge is a Node.js package that downloads executable files needed for its operation. The package insecurely downloads these files over unencrypted HTTP connections, allowing attackers positioned on the network path (such as on a public Wi-Fi network or compromised ISP) to intercept and replace the executable with malicious code. This results in arbitrary code execution on the system running slimerjs-edge.
Technical details
The vulnerability exists in slimerjs-edge's package installation process, which fetches a required executable over HTTP rather than HTTPS. This is a missing encryption issue (CWE-311) affecting the integrity and authenticity of downloaded resources. An attacker positioned on the network path (such as on a shared network, public Wi-Fi, or via BGP hijacking) can perform a man-in-the-middle attack to intercept the HTTP response and inject a malicious executable without requiring authentication or user interaction. Upon installation, the compromised executable will be executed with the privileges of the user running npm install, granting the attacker full code execution. No patch has been released for this vulnerability; the GitHub advisory recommends avoiding the package entirely or limiting its installation to private networks only.
Affected products
- slimerjs-edge contributors slimerjs-edge all versions
Timeline
- 2018-08-15: disclosed: Published to GitHub Advisory Database
- 2016: other: CVE-2016-10644 assigned (CVE date indicates earlier discovery)