NPM Repository Administrators the package , which contained a malicious insertion. The malicious package had gone unnoticed since August last year. Over the year, the attackers managed to release 7 new versions, which were downloaded around 200 times.
During the installation of the package, an executable file was run for Windows that transmitted confidential information to an external host. Users who installed the package are recommended to urgently change all encryption keys and accounts on the system, as well as carry out a system check for any backdoors left by the attackers (removing the package from the system does not guarantee the removal of related malware).
Additionally, it can be noted package manager updates , beginning with which files owned by the root user can only be created in directories owned by root (placing such files in regular user directories is prohibited). The new version also fixes an issue that caused crashes when the '—user' option referenced a non-existent user (this issue mostly affected Docker users). In 'npm ci', full access to all npm configuration values is provided.
Source: opennet.ru
