Executive brief
A popular Jekyll plugin for GitHub Projects contained malicious code in version 0.2.12 that stole sensitive customer data. When the package was used in a web application, the malicious code would extract passwords, credit card numbers, and CVC codes from form fields and exfiltrate them to an attacker-controlled server, putting customer data and payment information at risk.
Technical details
The jekyll-for-github-projects npm package version 0.2.12 contained intentionally malicious code that would execute in the browser and enumerate password, CVC, and card number fields from HTML forms. The stolen data was exfiltrated via HTTP requests to https://js-metrics.com/minjs.php. This is a supply-chain attack vector delivered through a compromised or intentionally malicious package published to the npm registry. The attack requires the malicious package to be installed and executed in a web application context. Users should immediately remove the affected version and evaluate systems for potential data compromise. Version 0.2.11 is recommended as a downgrade target.
Affected products
- jekyll-for-github-projects jekyll-for-github-projects 0.2.12
Timeline
- 2020-09-03: disclosed