A malicious package bb-builder has been detected in the NPM repository. NPM release 6.11

NPM Repository Administrators have blocked the package bb-builder, which contained a malicious insertion. The malicious package had gone unnoticed since August last year. Over the year, the attackers managed to release 7 new versions, which were downloaded around 200 times.

During the installation of the package, an executable file was run for Windows that transmitted confidential information to an external host. Users who installed the package are recommended to urgently change all encryption keys and accounts on the system, as well as carry out a system check for any backdoors left by the attackers (removing the package from the system does not guarantee the removal of related malware).

Additionally, it can be noted exit package manager updates NPM 6.11, beginning with which files owned by the root user can only be created in directories owned by root (placing such files in regular user directories is prohibited). The new version also fixes an issue that caused crashes when the '—user' option referenced a non-existent user (this issue mostly affected Docker users). In 'npm ci', full access to all npm configuration values is provided.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster