Junglewise Threat Intelligence

k0a_multer malicious package uploading system information

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

k0a_multer is a Node.js package for handling file uploads. A malicious version of this package was published that collected and transmitted sensitive system information (OS type, hostname) to remote servers without authorization. Any application using the compromised version could have its infrastructure details exposed to attackers.

Technical details

The vulnerability is classified as malicious code injection (CWE-506). An attacker published a compromised version of k0a_multer to npm that contained embedded code to exfiltrate system metadata (operating system and hostname) to an external server. The attack requires only that the package be installed and executed in a target environment; no authentication, special privileges, or user interaction is required. An attacker who successfully deploys this malicious package into a supply chain gains reconnaissance information about target systems that can inform further attacks. The recommended mitigation is immediate removal of the package.

Affected products

  • npm k0a_multer all versions (from 0.0.0 onwards)

Timeline

  • 2020-09-03: published: Advisory published on GitHub

References