A vulnerability that allowed an update to be released for any package in the NPM repository.

GitHub has revealed information about two incidents in the NPM package repository infrastructure. On November 2, external security researchers (Kajetan Grzybowski and Maciej Piechota) reported a vulnerability in the NPM repository through the Bug Bounty program, allowing the publication of a new version of any package using their own account, which was not authorized for such updates.

The vulnerability was caused by improper authorization checks in the code of the microservices handling requests to NPM. The authorization service performed access checks on packages based on the data provided in the request, but another service that uploaded updates to the repository determined the package for publication based on the metadata contained in the uploaded package. Thus, an attacker could request the publication of an update for their package, to which they have access, but specify in the package itself information about another package that would ultimately be updated.

The issue was resolved six hours after the vulnerability was disclosed, but the vulnerability had existed in NPM longer than the telemetry logs cover. GitHub claims there have been no recorded attacks using this vulnerability since September 2020, but there is no guarantee that the issue wasn't exploited prior to that.

The second incident occurred on October 26. During technical work on the database of the replicate.npmjs.com service, it was discovered that confidential data revealing the names of internal packages mentioned in the change log were present in a database accessible to external requests. Information about such names could be used to carry out dependency attacks in internal projects (in February, a similar attack allowed code execution on servers PayPal, Microsoft, Apple, Netflix, Uber, and 30 other companies).

Additionally, due to the increasing instances of repository hijacking of major projects and the spread of malicious code through the compromise of developer accounts, GitHub has decided to implement mandatory two-factor authentication. This change will take effect in the first quarter of 2022 and will apply to maintainers and administrators of packages included in the list of the most popular. Furthermore, there will be an upgrade to the infrastructure, which will introduce automated monitoring and analysis of new package versions to detect malicious changes early.

As a reminder, according to a study conducted in 2020, only 9.27% of package maintainers use two-factor authentication to protect their access, and in 13.37% of cases, developers attempted to reuse compromised passwords that appear in known password leaks when creating new accounts. During a password strength check, access was gained to 12% of accounts in NPM (13% of packages) due to the use of predictable and trivial passwords such as '123456'. Among the problematic cases were 4 user accounts from the Top 20 most popular packages, 13 accounts with packages that were downloaded more than 50 million times a month, 40 with over 10 million downloads a month, and 282 with more than 1 million downloads a month. Considering the loading of modules through dependency chains, compromising unreliable accounts could potentially affect up to 52% of all modules in NPM.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster