Junglewise Threat Intelligence

load-from-cwd-or-npm malicious package injection

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

Version 3.0.2 of the load-from-cwd-or-npm npm package contained malicious code that targeted the purescript-installer package. An attacker who installed this compromised version could execute arbitrary code on the developer's system during dependency resolution, potentially compromising build systems and software supply chains.

Technical details

Version 3.0.2 of the load-from-cwd-or-npm npm package was found to contain malicious code (CWE-506: Embedded Malicious Code). The malware was injected into the package and specifically targeted the purescript-installer package to break its functionality. The attack vector is network-based: any developer who installed the compromised version via npm package manager would pull the malicious code into their environment. No user interaction is required beyond the standard npm install operation. The compromise was fixed in version 3.0.4; there is no indication of further compromise beyond version 3.0.2.

Affected products

  • npm load-from-cwd-or-npm 3.0.2

Timeline

  • 2020-09-03: disclosed
  • 2020-09-03: patched: Fixed in version 3.0.4

References