The NPM package UAParser.js, which has 8 million downloads per week, has been compromised with malware.

The story of the removal of three malicious packages from the NPM repository, which copied the code of the UAParser.js library, took an unexpected turn — unknown attackers took control of the author’s account for the UAParser.js project and released updates containing code for stealing passwords and mining cryptocurrencies.

The problem is that the UAParser.js library, which offers functionality for parsing the User-Agent HTTP header, has around 8 million downloads a week and is used as a dependency in more than 1200 projects. The UAParser.js is reported to be applied in projects of companies such as Microsoft, Amazon, Facebook, Slack, Discord, Mozilla, Apple, ProtonMail, Autodesk, Reddit, Vimeo, Uber, Dell, IBM, Siemens, Oracle, HP, and Verizon.

The attack was carried out via a compromise of the developer’s account, who realized something was wrong after an unusual wave of spam flooded their inbox. How the developer’s account was compromised has not been disclosed. The attackers created releases 0.7.29, 0.8.0, and 1.0.0, injecting malicious code into them. Within a few hours, the developers regained control of the project and created updates 0.7.30, 0.8.1, and 1.0.1 to fix the issue. The malicious versions were published only as packages in the NPM repository. The project’s Git repository on GitHub was unaffected. All users who installed the problematic versions and found the jsextension file in Linux/macOS, and jsextension.exe and create.dll files in Windows, are advised to consider their systems compromised.

The added malicious changes resembled changes previously proposed in UAParser.js clones, which apparently were released for testing functionality prior to a large-scale attack on the main project. An executable file named jsextension was downloaded and launched on the user’s system from an external host, selected based on the user’s platform and supported operation in Linux, macOS, and Windows. For Windows platforms, in addition to the cryptocurrency mining program Monero (using the XMRig miner), the attackers also organized the injection of the create.dll library to intercept passwords and send them to an external host.

The code for download was added to the file preinstall.sh, which now includes the snippet IP=$(curl -k https://freegeoip.app/xml/ | grep ‘RU|UA|BY|KZ’) if [ -z "$IP" ] … download and execution of the executable file fi

As can be seen from the code, the script initially checked the IP address on the freegeoip.app service and did not launch the malicious application for users from Russia, Ukraine, Belarus, and Kazakhstan.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster