Junglewise Threat Intelligence

npm asnc malicious typosquatting package

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

The npm package 'asnc' was identified as a malicious library designed to trick developers through typosquatting. It mimics a popular package name to capture users who make a typing error during installation. Once installed, the package exfiltrates system information to a remote server, potentially exposing development environment details and administrative privileges.

Technical details

The 'asnc' package is a malicious npm library that utilizes typosquatting to target developers. Upon installation, it executes code that collects and exfiltrates metadata to a remote server, including the name of the package, the intended package name, the Node.js version, and whether the process is running with sudo/root privileges. This behavior is classified as CWE-506 (Embedded Malicious Code). All versions of the package are affected, and users are advised to remove the dependency immediately.

Affected products

  • npm asnc All versions

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-02: disclosed: Advisory published

References