Junglewise Threat Intelligence

sparkies malicious package exfiltrating system information

Severity: low · CVSS 3.1 · Published 2020-09-03

Vendors: npm.

Executive brief

The sparkies npm package contained malicious code that collected and transmitted system information (OS, hostname) to a remote attacker-controlled server. Users who installed this package risk having their system details exposed and potential further compromise of their environment.

Technical details

This is a supply-chain attack involving intentional injection of malicious code (CWE-506) into a published npm package. The malicious payload exfiltrates system metadata (OS type, hostname) over the network to an external server without user authorization or awareness. Attack vector is network-reachable upon package installation; no authentication or user interaction beyond the install action is required. The compromise is disclosed and the package should be immediately removed from all environments. No legitimate version of this package exists.

Affected products

  • npm sparkies 0.0.0 and above

Timeline

  • 2020-09-03: disclosed

References