Junglewise Threat Intelligence

rc-calendar-jhorst malicious code injection

Severity: info · Published 2020-09-01

Vendors: npm.

Executive brief

A malicious version of the rc-calendar-jhorst npm library was published with code that steals payment and password information from web forms and sends it to an attacker-controlled server. Any web application using version 8.4.3 of this component is at risk of exposing customer payment data and login credentials. Organizations should immediately audit their applications for this package version and migrate to a safe version.

Technical details

The malicious code in rc-calendar-jhorst version 8.4.3 performs client-side form harvesting of sensitive fields (password, cvc, cardnumber) and exfiltrates the captured values via HTTP requests to https://js-metrics.com/minjs.php?pl=. This is a supply chain attack delivered through the npm package ecosystem. The attack requires only that a vulnerable version be installed and executed in a browser context—no user interaction or authentication bypass is necessary. All applications using version 8.4.3 are compromised. Remediation requires replacement with version 8.4.2 or earlier, or any version after 8.4.3, along with assessment of whether sensitive user data was stolen during the exposure window.

Affected products

  • npm rc-calendar-jhorst 8.4.3

Timeline

  • 2020-09-01: disclosed: Malicious package version published and advisory released

References