A security issue has been identified in the NPM package repository, allowing the package owner to add any user as a maintainer without obtaining consent from that user and without informing them of the action taken. The problem is exacerbated by the fact that after adding a third-party user as a maintainer, the original author of the package could remove themselves from the maintainer list, leaving the third-party user as the sole responsible person for the package.
Malicious package creators could exploit this issue to add well-known developers or major companies as maintainers to increase user trust and create the illusion that respected developers are responsible for the package, while in reality, they have no connection to it and are not even aware of its existence. For example, an attacker could upload a malicious package, change the maintainer, and invite users to test a new development from a large company. This vulnerability could also be used to tarnish the reputation of certain developers by presenting them as initiators of questionable activities and malicious actions.
GitHub was notified of the issue on February 10 and resolved it on April 26 at npmjs.com by introducing mandatory confirmation for users' consent to join another project. Developers of many NPM packages have been advised to check if there are any bindings in their owned packages that were added without their consent.
Źródło: opennet.ru
