Executive brief
The 'getcookies' library, a tool used by developers to handle browser cookies, was found to contain malicious code. This backdoor allows an outside attacker to take full control of the server or computer where the software is installed. Organizations using this package should remove it immediately and investigate their systems for signs of unauthorized access.
Technical details
The 'getcookies' npm module contains embedded malicious code (CWE-506) that functions as a backdoor. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the host system via the network. The attack vector is direct and requires no user interaction or prior privileges. All versions of the package are considered compromised, and the recommended action is complete removal and a forensic audit of any systems where the package was deployed.
Affected products
- npm getcookies All versions
Timeline
- 2020-08-31: advisory: GitHub reviewed the advisory
- 2020-09-01: disclosed: Advisory published