Malicious changes have been detected in the dependencies of the npm package with the PureScript installer.

In the dependencies of the npm package with the PureScript installer detected malicious code appearing during the package installation attempt purescript. The malicious code is embedded through dependencies load-from-cwd-or-npm and rate-map. Notably, the original author of the npm package with the PureScript installer managed the packages with these dependencies until recently, but around a month ago, the package was handed over to other maintainers.

The issue was discovered by one of the new maintainers of the package, who was granted maintenance rights after many disagreements and unpleasant discussions with the original author of the purescript npm package. The new maintainers are responsible for the PureScript compiler and insisted that the npm package with its installer should be maintained by the same maintainers, not an outsider. The author of the npm package with the PureScript installer initially did not agree, but eventually conceded and transferred access to the repository. At the same time, some dependencies remained under his control.

Last week, the release of the PureScript compiler 0.13.2 was announced and
the new maintainers prepared a corresponding update for the npm package with the installer, which was found to contain malicious code in its dependencies. The former maintainer, who has been removed from the position, claimed that his account was compromised by unknown attackers. However, in its current form, the actions of the malicious code were limited to sabotaging the package's installation, which became the first version from the new maintainers. The malicious activity consisted of an endless loop producing an error message when attempting to install the package using the command 'npm i -g purescript' without any overt malicious activity.

Two attacks were identified. A few hours after the official release of the new version of the purescript npm package, someone created a new version of the dependency load-from-cwd-or-npm 3.0.2, the changes in which caused the call to loadFromCwdOrNpm() to return a stream PassThrough, mirroring input requests as output values.

Four days later, after the developers identified the source of the failures and prepared to release an update to exclude load-from-cwd-or-npm from dependencies, the attackers released another update of load-from-cwd-or-npm 3.0.4, in which the malicious code was removed. However, almost immediately, an update for another dependency rate-map 1.0.3 was released, which included a fix that blocked the callback call for loading. That is, in both cases, the changes in the new versions of load-from-cwd-or-npm and rate-map were characteristic of explicit sabotage. Moreover, the malicious code contained a check that activated the faulty actions only when installing a release from new maintainers and did not manifest during the installation of older versions.

The developers resolved the issue by releasing an update that removed the problematic dependencies. To prevent compromised code from settling on user systems after attempting to install the problematic version of PureScript, it is recommended to delete the contents of the node_modules directories and the package-lock.json files, and then set the minimum version of purescript to 0.13.2.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster