Executive brief
pizza-pasta is a npm package that was compromised with malicious code designed to steal sensitive information and alter the local system. Version 1.0.3 contains install scripts that create folders on the desktop, download files, and exfiltrate SSH keys—a serious threat to application security and data confidentiality for any developer who installed the affected package.
Technical details
The vulnerability is a supply chain attack involving malicious code injection into the pizza-pasta npm package (CWE-506: Embedded Malicious Code). Version 1.0.3 specifically contains malicious install scripts that execute during package installation with the privileges of the installing user. The attack vector is network-based; exploitation is automatic upon installation with no additional preconditions or user interaction required. The malicious payload creates folders on the system desktop, downloads an image from imgur.com, and prints SSH private keys to the console, enabling credential theft and potential unauthorized access to remote systems. No patch is available; users must remove the package entirely from their environment.
Affected products
- npm pizza-pasta 1.0.3
Timeline
- 2020-09-03: disclosed