Junglewise Threat Intelligence

pensi-scheduler malicious package in v1.1.3

Severity: info · Published 2020-09-03

Vendors: npm.

Executive brief

pensi-scheduler is a JavaScript scheduling library. Version 1.1.3 contained malicious code that steals sensitive payment and password data from web forms, sending this information to an attacker-controlled server. Any application using this compromised version exposed user credentials and payment card information to theft.

Technical details

The malicious code in pensi-scheduler v1.1.3 is a form-scraping attack that runs client-side in the browser. It enumerates HTML form fields matching patterns for passwords, credit card numbers, and CVC codes, then exfiltrates the collected values to an attacker server at https://js-metrics.com/minjs.php?pl=. The attack requires no user authentication or special privileges—it executes automatically when the library is loaded. The vulnerability affects v1.1.3 specifically, and mitigation involves removing the package and downgrading to v1.1.2 or later patched versions.

Affected products

  • pensi-scheduler 1.1.3

Timeline

  • 2020-09-03: disclosed

References