Executive brief
The tiar package, distributed via npm, contains malicious code that exfiltrates system information to a remote server, downloads arbitrary files, and executes them. Any system with this package installed should be considered fully compromised, and all credentials and secrets stored on that system must be rotated immediately from a clean device.
Technical details
All versions of the tiar npm package contain intentionally injected malicious code (CWE-506: Embedded Malicious Code). The package performs three key malicious actions upon installation or execution: collection and exfiltration of system information to an attacker-controlled remote server, remote file download capability, and arbitrary code execution. The attack vector is network-based with no authentication or user interaction required beyond the initial installation of the compromised package. An attacker gains full control over the compromised system, enabling data theft, lateral movement, and persistent compromise. There is no patch available; the entire package must be considered hostile and the system should be treated as fully compromised.
Affected products
- npm tiar all versions
Timeline
- 2020-09-03: disclosed: Malicious package publicly disclosed