Junglewise Threat Intelligence

CVE-2017-16126: botbait tracking module information disclosure

CVE-2017-16126 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

The botbait npm package is a malicious tracking module designed to collect sensitive information about users and their systems within the npm ecosystem. The module covertly records the source IP address, Node.js version details, platform information, and how the module was invoked, then transmits this data without user consent. Deploying this package exposes system and network information to unauthorized third parties and should be immediately removed from all environments.

Technical details

botbait is a reconnaissance module that implements unauthorized telemetry collection (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). The package tracks source IP, process.versions, process.platform, and module invocation method (test, require, pre-install) and exfiltrates this data to attacker-controlled infrastructure. The vulnerability is triggered automatically upon module import or installation with no authentication or user interaction required; the attack vector is network-based since data is transmitted to remote servers. The module has no legitimate functionality and should be uninstalled from all npm environments. No patching is available; the only mitigation is complete removal.

Affected products

  • npm botbait all versions from 0.0.0

Timeline

  • 2017-08-08: disclosed: Initial report by Adam Baldwin
  • 2017-09-26: advisory: Advisory published on npm
  • 2020-09-01: advisory: GHSA-4r5x-qjqc-p579 published

References