Executive brief
The npm package 'asnc' was identified as a malicious library designed to trick developers through typosquatting. It mimics a popular package name to capture users who make a typing error during installation. Once installed, the package exfiltrates system information to a remote server, potentially exposing development environment details and administrative privileges.
Technical details
The 'asnc' package is a malicious npm library that utilizes typosquatting to target developers. Upon installation, it executes code that collects and exfiltrates metadata to a remote server, including the name of the package, the intended package name, the Node.js version, and whether the process is running with sudo/root privileges. This behavior is classified as CWE-506 (Embedded Malicious Code). All versions of the package are affected, and users are advised to remove the dependency immediately.
Affected products
- npm asnc All versions
Timeline
- 2020-08-31: advisory: GitHub reviewed the advisory
- 2020-09-02: disclosed: Advisory published