Junglewise Threat Intelligence

midway-dataproxy malicious package with remote code execution

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

midway-dataproxy is a Node.js package used for data proxy functionality. All versions of this package contain malicious code that exfiltrates system information, downloads and executes arbitrary files, giving attackers complete control over any system where it is installed. Any organization using this package should consider their infrastructure fully compromised and immediately rotate all credentials and secrets.

Technical details

The vulnerability is a malicious package (CWE-506: Embedded Malicious Code) intentionally published to the npm registry. The package performs system reconnaissance by uploading system information to attacker-controlled servers, then downloads and executes arbitrary code on the host system. No authentication is required; exploitation occurs automatically upon package installation. This grants the attacker full code execution and control over the affected system. The malicious behavior affects all published versions. Complete removal may be insufficient if secondary malware was deployed.

Affected products

  • midway-dataproxy midway-dataproxy all versions

Timeline

  • 2020-09-03: disclosed

References