Junglewise Threat Intelligence

nothing-js malicious code execution via npm test

Severity: low · CVSS 3.1 · Published 2020-09-01

Vendors: npm.

Executive brief

The npm package 'nothing-js' has been identified as malicious software. It contains code designed to delete all files on a system when the standard testing command is executed. This could lead to total data loss and operational disruption for any developer or automated system that installs and tests the package.

Technical details

The 'nothing-js' package is a malicious library distributed via the npm registry. It leverages the 'test' lifecycle script in the package.json to execute a destructive command. When a user or CI/CD pipeline runs 'npm test', the script attempts to recursively delete all files on the filesystem. This is classified as CWE-506 (Embedded Malicious Code). The package has been unpublished from the npm registry, and any existing installations should be immediately removed.

Affected products

  • nothing-js nothing-js All versions

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-01: disclosed: Advisory published

References