Junglewise Threat Intelligence

owl-orchard-apple-sunshine malicious package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The npm package owl-orchard-apple-sunshine contains malicious code that executes a reverse shell script on installation, granting an attacker complete remote access to the infected system. Any system with this package installed should be considered fully compromised; all credentials and secrets must be rotated from a clean device, and complete removal cannot be guaranteed without forensic remediation.

Technical details

This malicious npm package (CWE-506: Embedded Malicious Code) downloads and executes a reverse shell payload during installation, providing the package author with unauthorized remote access to the host system. The attack vector is network-based and requires no authentication or user interaction beyond installing the package. The vulnerability affects all versions of owl-orchard-apple-sunshine and gives an attacker full system-level control, enabling data exfiltration, lateral movement, and persistence. No patch is available; the only mitigation is removal of the package and complete system remediation.

Affected products

  • npm owl-orchard-apple-sunshine all versions

Timeline

  • 2020-09-03: disclosed

References