Executive brief
resourcehacker is a Node.js library used to manipulate Windows resource files. The package downloads an executable over unencrypted HTTP during installation, allowing an attacker on the network path to intercept and replace it with malicious code, leading to remote code execution on the user's system.
Technical details
resourcehacker contains an insecure download vulnerability (CWE-311: Missing Encryption of Sensitive Data) where an executable is fetched over unencrypted HTTP during package installation. An attacker with network access (man-in-the-middle position) can intercept the HTTP response and replace the legitimate executable with malicious code, achieving code execution on the affected system. This requires the attacker to have a privileged network position such as control of the local network, ISP access, or DNS spoofing capability. No patch has been released; the only mitigation is to avoid using the package or to restrict installation to trusted private networks only.
Affected products
- npm resourcehacker all versions
Timeline
- 2018-08-15: disclosed
- 2020-06-16: other: GitHub reviewed and confirmed