Junglewise Threat Intelligence

soket.io malicious package with command and control communication

Severity: low · CVSS 3.1 · Published 2020-09-01

Vendors: npm.

Executive brief

soket.io is a malicious npm package designed to deceive developers who mistype the popular "socket.io" library name. Once installed, the package establishes contact with an attacker-controlled server to execute arbitrary commands on the developer's machine. Installation of this package enables complete system compromise, including credential theft and code injection into legitimate projects.

Technical details

soket.io is a typosquatting attack using a malicious npm package designed to exploit developers who mistype "socket.io". The package implements CWE-506 (embedded malicious code) and executes a reverse shell callback to a command and control server upon installation, without any user authentication or special preconditions beyond running npm install. An attacker gains immediate arbitrary command execution in the context of the developer's user account, enabling credential exfiltration, supply chain poisoning, and lateral movement. The package was removed from npm Registry shortly after publication; no patch exists as the package itself is the attack vector.

Affected products

  • npm soket.io all versions

Timeline

  • 2020-09-01: disclosed
  • 2020-09-01: advisory: Published to npm Registry for brief period then removed

References