Junglewise Threat Intelligence

CVE-2017-16204: npm jquey malware - SSH key and bash history exfiltration

CVE-2017-16204 · Severity: info · Published 2018-08-06

Vendors: npm.

Executive brief

The jquey npm package is malware designed to steal sensitive data from developers' systems. When installed, it searches for and exfiltrates private SSH keys, bash history, and other credentials to attacker-controlled servers. Any organization using this package must regenerate all SSH keys, API tokens, and other secrets that may have been compromised.

Technical details

This is embedded malicious code (CWE-506) distributed through the npm package registry. The jquey package (version 1.0.1 and all 1.x versions) contains a malware payload that automatically executes upon installation, enumerating and exfiltrating sensitive files including ~/.ssh (private keys) and ~/.bash_history to remote attacker-controlled locations. The attack vector is supply chain / package installation—any developer who runs npm install with jquey as a dependency triggers the malicious code with their user's privileges. The package has been unpublished from npm, but may persist in private repositories or cached installations. No patch exists; the only remediation is complete removal and credential regeneration.

Affected products

  • npm jquey 1.x (including 1.0.1)

Timeline

  • 2018-08-06: disclosed