An attack on NPM that allows the discovery of packages in private repositories

A flaw has been identified in NPM that allows the determination of the existence of packages in private repositories. The issue arises from the varying response times when querying an existing versus a non-existing package by an external user without access to the repository. In the absence of access to any packages in private repositories, the server registry.npmjs.org returns a '404' error, but if a package with the requested name exists, the error is returned after a noticeable delay. An attacker can exploit this characteristic to ascertain the presence of a package by guessing package names from dictionaries.

Determining package names in private repositories may be necessary for conducting a dependency confusion attack that manipulates the overlap of dependency names in public and internal repositories. By knowing which internal NPM packages are present in corporate repositories, an attacker can publish packages with the same names and newer version numbers in the public NPM repository. If internal libraries are not explicitly bound in the configuration to their repository during the build, the npm package manager will consider the public repository more prioritized and download the package prepared by the attacker.

GitHub was notified of the issue in March but declined to add protection against the attack, citing architectural limitations. Companies using private repositories are advised to periodically check for overlapping names in the public repository or to create stubs under their name that replicate the names of packages in private repositories, so that malicious actors cannot publish their packages with overlapping names.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster