{"id":36164,"date":"2019-10-31T22:09:56","date_gmt":"2019-10-31T19:09:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya\/"},"modified":"2019-10-31T22:09:56","modified_gmt":"2019-10-31T19:09:56","slug":"v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya","title":{"rendered":"Malicious changes have been detected in the dependencies of the npm package with the PureScript installer.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>In the dependencies of the npm package with the PureScript installer <noindex><a rel=\"nofollow\" href=\"https:\/\/harry.garrood.me\/blog\/malicious-code-in-purescript-npm-installer\/\">detected<\/a><\/noindex> malicious code appearing during the package installation attempt <noindex><a rel=\"nofollow\" href=\"https:\/\/www.npmjs.com\/package\/purescript\">purescript<\/a><\/noindex>. The malicious code is embedded through dependencies <noindex><a rel=\"nofollow\" href=\"https:\/\/npmjs.com\/package\/load-from-cwd-or-npm\">load-from-cwd-or-npm<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/npmjs.com\/package\/rate-map\">rate-map<\/a><\/noindex>. Notably, the original author of the npm package with the PureScript installer managed the packages with these dependencies until recently, but around a month ago, the package was handed over to other maintainers. <\/p>\n<p> The issue was discovered by one of the new maintainers of the package, who was granted maintenance rights after many disagreements and unpleasant discussions with the original author of the purescript npm package. The new maintainers are responsible for the PureScript compiler and insisted that the npm package with its installer should be maintained by the same maintainers, not an outsider. The author of the npm package with the PureScript installer initially did not agree, but eventually conceded and transferred access to the repository. At the same time, some dependencies remained under his control.<\/p>\n<p>Last week, the release of the PureScript compiler 0.13.2 was announced and<br \/>\nThe new maintainers prepared an appropriate update for the npm package installer, which was found to contain malicious code in its dependencies. The previous maintainer of the PureScript package installer reported that their account had been compromised by unknown attackers. However, as it stands, the malicious activities were limited to sabotaging the installation of the package, which was the first version from the new maintainers. The malicious actions involved an infinite loop that produced an error message when attempting to install the package using the command 'npm i -g purescript' without carrying out any explicit malicious activity.<\/p>\n<p>Two attacks were identified. A few hours after the official release of the new version of the purescript npm package, someone created a new version of the dependency load-from-cwd-or-npm 3.0.2, the changes in which caused the call to loadFromCwdOrNpm() to return a stream <noindex><a rel=\"nofollow\" href=\"https:\/\/nodejs.org\/api\/stream.html#stream_class_stream_passthrough\">PassThrough<\/a><\/noindex>, mirroring input requests as output values. <\/p>\n<p>Four days later, after the developers identified the source of the failures and prepared to release an update to exclude load-from-cwd-or-npm from dependencies, the attackers released another update of load-from-cwd-or-npm 3.0.4, in which the malicious code was removed. However, almost immediately, an update for another dependency rate-map 1.0.3 was released, which included a fix that blocked the callback call for loading. That is, in both cases, the changes in the new versions of load-from-cwd-or-npm and rate-map were characteristic of explicit sabotage. Moreover, the malicious code contained a check that activated the faulty actions only when installing a release from new maintainers and did not manifest during the installation of older versions.<\/p>\n<p>The developers resolved the issue by releasing an update that removed the problematic dependencies. To prevent compromised code from settling on user systems after attempting to install the problematic version of PureScript, it is recommended to delete the contents of the node_modules directories and the package-lock.json files, and then set the minimum version of purescript to 0.13.2.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51093\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u043a npm-\u043f\u0430\u043a\u0435\u0442\u0443 \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0449\u0438\u043a\u043e\u043c PureScript \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f \u043f\u0440\u0438 \u043f\u043e\u043f\u044b\u0442\u043a\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043f\u0430\u043a\u0435\u0442\u0430 purescript. \u0412\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434 \u0432\u0441\u0442\u0440\u043e\u0435\u043d \u0447\u0435\u0440\u0435\u0437 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 load-from-cwd-or-npm \u0438 rate-map. \u041f\u0440\u0438\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u043e, \u0447\u0442\u043e \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u0441 \u0434\u0430\u043d\u043d\u044b\u043c\u0438 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u043c\u0438 \u0437\u0430\u043d\u0438\u043c\u0430\u0435\u0442\u0441\u044f \u0438\u0437\u043d\u0430\u0447\u0430\u043b\u044c\u043d\u044b\u0439 \u0430\u0432\u0442\u043e\u0440 npm-\u043f\u0430\u043a\u0435\u0442\u0430 \u0441 \u0438\u043d\u0441\u0442\u0430\u043b\u043b\u044f\u0442\u043e\u0440\u043e\u043c PureScript, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0434\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u0438\u0445 \u043f\u043e\u0440 \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u0434\u0430\u043d\u043d\u043e\u0433\u043e npm-\u043f\u0430\u043a\u0435\u0442\u0430, \u043d\u043e \u043e\u043a\u043e\u043b\u043e \u043c\u0435\u0441\u044f\u0446\u0430 \u043d\u0430\u0437\u0430\u0434 \u043f\u0430\u043a\u0435\u0442 \u043f\u0435\u0440\u0435\u0448\u0451\u043b \u043a \u0434\u0440\u0443\u0433\u0438\u043c \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0430\u044e\u0449\u0438\u043c. [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-36164","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u043a npm-\u043f\u0430\u043a\u0435\u0442\u0443 \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0449\u0438\u043a\u043e\u043c PureScript \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u043a npm-\u043f\u0430\u043a\u0435\u0442\u0443 \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0449\u0438\u043a\u043e\u043c PureScript \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u043a npm-\u043f\u0430\u043a\u0435\u0442\u0443 \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0449\u0438\u043a\u043e\u043c PureScript \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:09:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:09:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Malicious changes have been found in the dependencies of the npm package with the PureScript installer | ProHoster","description":"Malicious code has been detected in the dependencies of the npm package with the PureScript installer.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u043a npm-\u043f\u0430\u043a\u0435\u0442\u0443 \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0449\u0438\u043a\u043e\u043c PureScript \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f | ProHoster","og:description":"\u0412 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u044f\u0445 \u043a npm-\u043f\u0430\u043a\u0435\u0442\u0443 \u0441 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u0449\u0438\u043a\u043e\u043c PureScript \u0432\u044b\u044f\u0432\u043b\u0435\u043d \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0438\u0439\u0441\u044f.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-zavisimostyah-k-npm-paketu-s-ustanovshhikom-purescript-vyyavleny-vredonosnye-izmeneniya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:09:56+00:00","article:modified_time":"2019-10-31T19:09:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"36164","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-22 02:17:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:49:43","updated":"2026-01-22 02:17:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/36164","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=36164"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/36164\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=36164"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=36164"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=36164"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}