Executive brief
pensi-scheduler is a JavaScript scheduling library. Version 1.1.3 contained malicious code that steals sensitive payment and password data from web forms, sending this information to an attacker-controlled server. Any application using this compromised version exposed user credentials and payment card information to theft.
Technical details
The malicious code in pensi-scheduler v1.1.3 is a form-scraping attack that runs client-side in the browser. It enumerates HTML form fields matching patterns for passwords, credit card numbers, and CVC codes, then exfiltrates the collected values to an attacker server at https://js-metrics.com/minjs.php?pl=. The attack requires no user authentication or special privileges—it executes automatically when the library is loaded. The vulnerability affects v1.1.3 specifically, and mitigation involves removing the package and downgrading to v1.1.2 or later patched versions.
Affected products
- pensi-scheduler 1.1.3
Timeline
- 2020-09-03: disclosed