Executive brief
The npm package owl-orchard-apple-sunshine contains malicious code that executes a reverse shell script on installation, granting an attacker complete remote access to the infected system. Any system with this package installed should be considered fully compromised; all credentials and secrets must be rotated from a clean device, and complete removal cannot be guaranteed without forensic remediation.
Technical details
This malicious npm package (CWE-506: Embedded Malicious Code) downloads and executes a reverse shell payload during installation, providing the package author with unauthorized remote access to the host system. The attack vector is network-based and requires no authentication or user interaction beyond installing the package. The vulnerability affects all versions of owl-orchard-apple-sunshine and gives an attacker full system-level control, enabling data exfiltration, lateral movement, and persistence. No patch is available; the only mitigation is removal of the package and complete system remediation.
Affected products
- npm owl-orchard-apple-sunshine all versions
Timeline
- 2020-09-03: disclosed