Junglewise Threat Intelligence

npm tiar malicious package with remote code execution

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The tiar package, distributed via npm, contains malicious code that exfiltrates system information to a remote server, downloads arbitrary files, and executes them. Any system with this package installed should be considered fully compromised, and all credentials and secrets stored on that system must be rotated immediately from a clean device.

Technical details

All versions of the tiar npm package contain intentionally injected malicious code (CWE-506: Embedded Malicious Code). The package performs three key malicious actions upon installation or execution: collection and exfiltration of system information to an attacker-controlled remote server, remote file download capability, and arbitrary code execution. The attack vector is network-based with no authentication or user interaction required beyond the initial installation of the compromised package. An attacker gains full control over the compromised system, enabling data theft, lateral movement, and persistent compromise. There is no patch available; the entire package must be considered hostile and the system should be treated as fully compromised.

Affected products

  • npm tiar all versions

Timeline

  • 2020-09-03: disclosed: Malicious package publicly disclosed

References