Junglewise Threat Intelligence

npm river-mock malicious code execution

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package 'river-mock' has been identified as containing malicious code designed to compromise any system where it is installed. The package automatically steals system information and can download and run additional unauthorized software. Organizations should assume any machine with this package is fully compromised and immediately rotate all passwords, secrets, and access keys.

Technical details

The 'river-mock' npm package contains a malicious payload classified under CWE-506 (Embedded Malicious Code). Upon installation or execution, the package exfiltrates sensitive system information to a remote server and subsequently downloads and executes an external file. This provides the attacker with full remote code execution (RCE) capabilities on the host machine. Because the package is inherently malicious, there is no patch; users must remove the package and perform a full incident response, including rotating all credentials stored on the affected system.

Affected products

  • npm river-mock All versions

Timeline

  • 2020-08-31: advisory: GitHub reviewed the advisory
  • 2020-09-03: disclosed: Advisory published

References