Executive brief
The npm package 'nothing-js' has been identified as malicious software. It contains code designed to delete all files on a system when the standard testing command is executed. This could lead to total data loss and operational disruption for any developer or automated system that installs and tests the package.
Technical details
The 'nothing-js' package is a malicious library distributed via the npm registry. It leverages the 'test' lifecycle script in the package.json to execute a destructive command. When a user or CI/CD pipeline runs 'npm test', the script attempts to recursively delete all files on the filesystem. This is classified as CWE-506 (Embedded Malicious Code). The package has been unpublished from the npm registry, and any existing installations should be immediately removed.
Affected products
- nothing-js nothing-js All versions
Timeline
- 2020-08-31: advisory: GitHub reviewed the advisory
- 2020-09-01: disclosed: Advisory published