News: 1604444422

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Malicious backdoored NPM package masqueraded as Twilio library for three days until it was turfed out

(2020/11/04)


GitHub's NPM on Monday removed a JavaScript library called twilio-npm because it contained malicious code, which has become something of a recurring theme for the open-source JavaScript code registry.

The offending library, designed to backdoor a victim's device and allow remote code execution, was [1]spotted by Sonatype , the security biz that flagged another malicious NPM Registry package called [2]electorn last month.

According to Ax Sharma, security engineer at Sonatype, twilio-npm has nothing to do with Twilio, a company that provides programmatic telephony services. But he speculates that the [3]popularity of official Twilio NPM packages , some of which get downloaded close to half a million times each day, motivated the miscreants behind twilio-npm<c/ode> to co-opt the company name.

The twilio-npm package didn't stick around long enough to dupe many people, however. Uploaded on Friday, October, 30, Sontatype's Release Integrity service apparently flagged the code as suspicious a day later – AI and machine learning evidently have some uses. On Monday, November 2, the biz published its findings, and the code was removed.

The [4]NPM advisory said the package opens a reverse shell to a remote server. "Any computer that has this package installed or running should be considered fully compromised," the notice stated. "All secrets and keys stored on that computer should be rotated immediately from a different computer."

The code does so through a post-install script, designed to run after the malicious library is fetched from the NPM Registry and installed. The script opens a TCP reverse shell using a service called ngrok.io, a legitimate developer tool that provides a way to expose local servers behind network barriers to the public internet.

It's unlikely that many people were deceived into installing the malicious library, however. Sharma said there were only 371 downloads during the brief time the code was available. And many of these initial requests are likely to have come from scanning engines and proxies that aim to keep track of changes to the NPM Registry.

Even so, the incident isn't an isolated event. Last month alone, [5]six NPM packages were flagged for being malicious. And this has been [6]going on for years .

A research paper released in September [7]argued the NPM ecosystem isn't as risky as it may seem. However, that study focused on vulnerabilities incorporated into libraries rather than deliberate attempts to sabotage packages with malicious code.

"Open source software is being published and consumed every day at an increasingly massive scale, yet most security protections still rely on community trust and human oversight – which can be easily abused," said AJ Brown, product manager at Sonatype. ®

Get our [8]Tech Resources



[1] https://blog.sonatype.com/twilio-npm-is-brandjacking-malware-in-disguise

[2] https://www.npmjs.com/advisories/1562

[3] https://www.npmjs.com/search?q=twilio&ranking=popularity

[4] https://www.npmjs.com/advisories/1574

[5] https://www.npmjs.com/advisories

[6] https://www.google.com/search?q=%22malicious+package%22+site:https://www.npmjs.com/advisories

[7] https://www.theregister.com/2020/09/25/npm_security_risks/

[8] https://whitepapers.theregister.com/

A man pleaded innocent of any wrong doing when caught by the police
during a raid at the home of a mobster, excusing himself by claiming that he
was making a bolt for the door.