Junglewise Threat Intelligence

requst typosquatting with telemetry collection

Severity: low · CVSS 3.1 · Published 2020-09-11

Vendors: npm.

Executive brief

The requst package is a malicious typosquatting attack targeting developers who mistype the popular "request" HTTP library name. Once installed, it silently collects and transmits telemetry data to a remote server, including package names, Node version, and whether the process runs with elevated privileges. This compromises developer security posture and can expose sensitive environment information.

Technical details

The vulnerability is a malicious package injection attack (CWE-506: Embedded Malicious Code). The requst package intentionally mimics the legitimate "request" library through typosquatting, then executes data harvesting code at installation time. The attack collects the intended package name, downloaded package name, Node version, and sudo privilege status, uploading this to an attacker-controlled remote server. Attack vector is network-based via package manager; requires a developer to mistype the package name during installation. No authentication required. The payload executes during npm install, giving the attacker full visibility into deployment environments.

Affected products

  • npm requst all versions

Timeline

  • 2020-09-11: disclosed

References