Npm Team Warns of New 'Binary Planting' Bug

Peter Reutemann <[email protected]> Tue, 17 Dec 2019 08:49:27 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LeWKG5BSu+n+HFCQO_bJPBDHp_78HBbOGNdfTTHSVVug@mail.gmail.com>
' The team behind npm, the biggest package manager for JavaScript
libraries, issued a security alert yesterday, advising all users to
update to the latest version (6.13.4) to prevent "binary planting"
attacks. From a report:

Npm (Node.js Package Manager) devs say the npm command-line interface
(CLI) client is impacted by a security bug -- a combination between a
file traversal and an arbitrary file (over)write issue. The bug can be
exploited by attackers to plant malicious binaries or overwrite files
on a user's computer. The vulnerability can be exploited only during
the installation of a boobytrapped npm package via the npm CLI.
"However, as we have seen in the past, this is not an insurmountable
barrier," said the npm team, referring to past incidents where
attackers planed backdoored or boobytrapped packages on the official
npm repository. Npm devs say they've been scanning the npm portal for
packages that may contain exploit code designed to exploit this bug,
but have not seen any suspicious cases. "That does not guarantee that
it hasn't been used, but it does mean that it isn't currently being
used in published packages on the [official npm] registry," npm devs
said.'

-- source: https://it.slashdot.org/story/19/12/16/1513245

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz