Junglewise Threat Intelligence

reqest malicious package with user tracking

Severity: low · CVSS 3.1 · Published 2020-09-02

Vendors: npm.

Executive brief

The "reqest" package is a malicious typosquatter that tricks developers into installing it instead of a legitimate similarly-named package. Once installed, it silently collects and sends information about the developer's environment (package names, Node version, sudo status) to a remote server, creating a supply chain risk and potential foothold for further compromise.

Technical details

This is a malicious package attack (CWE-506) exploiting typosquatting—intentional name similarity to a legitimate npm package. The vulnerability is a "trojanized" dependency: when installed (no authentication or special preconditions required; the attacker controls the package), the code immediately exfiltrates metadata to a remote server including the intended package name, installed package name, Node.js version, and whether the process has sudo privileges. This provides reconnaissance for targeted supply chain attacks. The only mitigation is immediate removal from dependencies; there is no patch, as the package itself is malicious.

Affected products

  • npm reqest

Timeline

  • 2020-09-02: disclosed

References