Executive brief
sdfjghlkfjdshlkjdhsfg is an npm package that contains malicious code designed to steal and compromise user accounts. When installed, the package acts as a worm that automatically discovers all other packages the user owns on npm, injects itself into their preinstall scripts, and publishes malicious new versions—enabling rapid lateral spread across the npm ecosystem and compromising the integrity of hundreds of packages. Organizations should immediately remove this package and audit all their published packages for signs of compromise.
Technical details
This npm package contains intentionally malicious code (CWE-506: Embedded Malicious Code) disguised as a legitimate library. All versions are affected. Upon installation, the package enumerates all npm packages owned by the authenticated user, modifies their preinstall scripts to execute the worm payload, and publishes new compromised versions back to the registry—all without user consent. The attack requires only that the package be installed in an environment where the user has npm credentials available; no special privileges or user interaction beyond installation is needed. The worm propagates automatically to every package the user controls, creating a supply-chain compromise vector affecting downstream consumers. No patch exists for this malicious package; complete removal and environment remediation are required.
Affected products
- npm sdfjghlkfjdshlkjdhsfg all versions
Timeline
- 2020-09-03: disclosed