Junglewise Threat Intelligence

kraken-api malicious package with command execution

Severity: info · Published 2020-09-02

Vendors: npm.

Executive brief

kraken-api is a JavaScript library for interacting with cryptocurrency exchange APIs. Version 0.1.8 contained malicious code that executes during installation, connecting to an attacker-controlled server to download and run arbitrary commands. Any system with this version installed should be considered fully compromised; all credentials and secrets must be rotated immediately from a clean machine.

Technical details

This is a supply-chain attack via a malicious npm package. The vulnerable version 0.1.8 includes malicious code in the postinstall script that runs automatically during package installation. Upon execution, the script contacts a command-and-control server to fetch and execute arbitrary commands with the privileges of the user who installed the package. The attack vector is local installation via npm; no network access or authentication bypass is required beyond running npm install. Once installed, an attacker gains full code execution and can exfiltrate secrets, install additional malware, or pivot through the compromised system. The only mitigation is to downgrade to version 0.1.7 or uninstall entirely, though complete removal of malicious artifacts is not guaranteed.

Affected products

  • npm kraken-api 0.1.8

Timeline

  • 2020-09-02: disclosed

References