Executive brief
soket.io is a malicious npm package designed to deceive developers who mistype the popular "socket.io" library name. Once installed, the package establishes contact with an attacker-controlled server to execute arbitrary commands on the developer's machine. Installation of this package enables complete system compromise, including credential theft and code injection into legitimate projects.
Technical details
soket.io is a typosquatting attack using a malicious npm package designed to exploit developers who mistype "socket.io". The package implements CWE-506 (embedded malicious code) and executes a reverse shell callback to a command and control server upon installation, without any user authentication or special preconditions beyond running npm install. An attacker gains immediate arbitrary command execution in the context of the developer's user account, enabling credential exfiltration, supply chain poisoning, and lateral movement. The package was removed from npm Registry shortly after publication; no patch exists as the package itself is the attack vector.
Affected products
- npm soket.io all versions
Timeline
- 2020-09-01: disclosed
- 2020-09-01: advisory: Published to npm Registry for brief period then removed