Junglewise Threat Intelligence

CVE-2017-16206: npm cofee-script malware credential theft

CVE-2017-16206 · Severity: low · CVSS 3 · Published 2018-08-06

Vendors: npm.

Executive brief

The cofee-script package, published on npm, is malware that automatically steals sensitive credentials and system files from an infected developer machine, including SSH private keys, authentication tokens, and command-line history, then exfiltrates them to attacker-controlled servers. Installation of this package compromises all developer credentials and grants attackers access to any service the victim can reach, putting organizational infrastructure and customer data at risk.

Technical details

cofee-script is a malicious npm package (CWE-200: Exposure of Sensitive Information) that executes credential-stealing code upon installation. The attack vector is network-based and requires no authentication or user interaction beyond installing the package—a victim simply needs to add it as a dependency or install it directly. The malware harvests private SSH keys, bash history, and other sensitive artifacts from the user's home directory and transmits them over the network to attacker-controlled infrastructure. All versions have been unpublished from the npm registry, but the damage occurs at installation time, making prevention of package installation the only mitigation; no patch exists for deployed systems.

Affected products

  • npm cofee-script 1.0.1 and related versions in the 1.x series

Timeline

  • 2018-08-06: disclosed: Published to GitHub Advisory Database