Junglewise Threat Intelligence

npm rrequest typosquatting with telemetry exfiltration

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

The rrequest npm package was a malicious typosquatting attack targeting developers who accidentally installed it instead of the legitimate similarly-named package. The malicious package secretly collected and transmitted installation metadata (package names, Node version, sudo status) to a remote server, enabling attackers to track which developers fell for the mistake and profile their development environments.

Technical details

This is a malicious open-source package published intentionally as a typosquatting attack on npm. The rrequest package mimicked a legitimate similarly-named package and was designed to deceive developers into installing it through typing mistakes. Upon installation and execution, the package silently exfiltrated metadata over the network to attacker-controlled infrastructure, including the package name downloaded, the intended target package name, Node version, and process privileges (sudo status). No further code execution compromise occurs, but the telemetry enables attackers to profile developer environments and track installation mistakes. Complete removal of the package is the only remediation.

Affected products

  • npm rrequest all

Timeline

  • 2020-09-02: disclosed
  • 2020-09-02: advisory

References