Junglewise Threat Intelligence

qingting malicious package

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The qingting npm package is a JavaScript library available on the npm package registry. All versions of this package contain intentionally malicious code designed to steal system information, download and execute arbitrary programs on affected computers. Any system with this package installed should be considered fully compromised, and all credentials and secrets stored on that system must be immediately rotated from a clean device.

Technical details

This is a supply-chain attack via a malicious package deliberately introduced into the npm registry. The qingting package contains code that performs reconnaissance (system information exfiltration), arbitrary code execution (downloads and runs remote files), and persistence mechanisms. The attack vector is installation of the affected package through npm, which requires developer action (npm install). The impact is complete system compromise with remote code execution capabilities. All versions from 0.0.0 onward are affected. No patch is available; the package should be completely removed and avoided.

Affected products

  • npm qingting all versions from 0.0.0 onward

Timeline

  • 2020-09-03: disclosed: Advisory published

References