Executive brief
The malicious-npm-package is an npm library (JavaScript package) that contains intentional malware designed to compromise Windows computers. When installed, the package automatically downloads and runs malicious software from an external server with full system privileges. Any developer or system that has used this package should assume complete system compromise and immediately revoke all credentials and secrets from a clean machine.
Technical details
This is a malicious package (CWE-506: Embedded Malicious Code) distributed via the npm registry. All versions of malicious-npm-package contain a malware payload that specifically targets Windows systems. The attack vector is network-based with no authentication required—exploitation occurs upon package installation. The payload executes a PowerShell command that downloads an executable file from a remote attacker-controlled server and executes it with the privileges of the installing user. The impact is complete system compromise. No patch is available; the only mitigation is removal of the package and full system remediation from a clean machine.
Affected products
- npm malicious-npm-package all versions
Timeline
- 2020-09-04: disclosed