Junglewise Threat Intelligence

CVE-2017-16072: nodemailer.js malware environment variable exfiltration

CVE-2017-16072 · Severity: low · CVSS 3 · Published 2018-08-29

Vendors: npm.

Executive brief

nodemailer.js is a malicious npm package designed to steal environment variables from developer machines and send them to attacker-controlled servers. Environment variables commonly contain database credentials, API keys, and deployment tokens. Installation of this package puts an organization's infrastructure and customer data at risk of compromise.

Technical details

This is an embedded malware vulnerability (CWE-506) in the npm package nodemailer.js that exfiltrates environment variables to remote attacker-controlled locations. The malicious code executes at package installation time with no privileges required and no user interaction beyond the initial install. All versions through 1.0.2 are affected. The attack vector is network-based, as an attacker can trick developers into installing the package (e.g., via typosquatting or supply chain compromise). All versions have been unpublished from npm, but affected systems must regenerate credentials to mitigate potential exposure.

Affected products

  • npm nodemailer.js all versions through 1.0.2

Timeline

  • 2018-08-29: disclosed: Advisory published to GitHub Advisory Database

Related threats