Junglewise Threat Intelligence

sj-labc malicious package with reverse shell

Severity: low · CVSS 3.1 · Published 2020-09-04

Vendors: npm.

Executive brief

The npm package sj-labc contains malicious code that downloads and executes a script to establish a reverse shell on infected systems, granting an attacker complete control. Any system with this package installed should be considered fully compromised, with all credentials and secrets rotated immediately from a clean device. Even after removal, residual malware may remain due to the attacker's full system access.

Technical details

sj-labc is an npm package containing embedded malicious code (CWE-506: Embedded Malicious Code). Upon installation and execution, the package downloads and runs a remote script that opens a reverse shell, granting an attacker complete command execution and system control. The attack requires only that the package be installed—no special privileges, user interaction, or network preconditions beyond standard outbound connectivity are needed. An attacker gains full system compromise with ability to exfiltrate data, install persistent backdoors, and pivot to other systems. All versions are affected, and no patched version exists; the only mitigation is complete avoidance and removal (though removal alone may not eliminate malware already deployed).

Affected products

  • sj-labc sj-labc all versions

Timeline

  • 2020-09-04: disclosed

References