Executive brief
The sparkies npm package contained malicious code that collected and transmitted system information (OS, hostname) to a remote attacker-controlled server. Users who installed this package risk having their system details exposed and potential further compromise of their environment.
Technical details
This is a supply-chain attack involving intentional injection of malicious code (CWE-506) into a published npm package. The malicious payload exfiltrates system metadata (OS type, hostname) over the network to an external server without user authorization or awareness. Attack vector is network-reachable upon package installation; no authentication or user interaction beyond the install action is required. The compromise is disclosed and the package should be immediately removed from all environments. No legitimate version of this package exists.
Affected products
- npm sparkies 0.0.0 and above
Timeline
- 2020-09-03: disclosed