Junglewise Threat Intelligence

sailclothjs malicious package

Severity: info · Published 2020-09-03

Vendors: npm.

Executive brief

sailclothjs is a JavaScript library used in web applications. Version 1.2.6 contained malicious code that, when executed in a browser, would steal sensitive payment and password information from web forms and exfiltrate it to a remote server. This represents a direct threat to customer financial data and account credentials.

Technical details

Version 1.2.6 of the sailclothjs npm package contained malicious code that would enumerate password, CVC, and card number fields from HTML forms in the browser and send the extracted values to https://js-metrics.com/minjs.php?pl=. The attack vector is the installation and execution of the compromised package in client-side JavaScript environments. No authentication or special preconditions are required—any web application using the malicious version would automatically exfiltrate sensitive data from users. The vulnerability affects version 1.2.6 specifically; users are recommended to downgrade to 1.2.5 or remove the package entirely.

Affected products

  • sailclothjs sailclothjs 1.2.6

Timeline

  • 2020-09-03: disclosed

References