Hackers Can Target Mailchimp Users By Exploiting a Dependency Confusion Bug
ID: 32159483-4e37-53e7-ac97-e5c9403f03ec
STIX ID: report--32159483-4e37-53e7-ac97-e5c9403f03ec
Feed Name: CloudSEK Blog
BeVigil and CloudSEK researchers discovered that Mailchimp's API documentation directs users to install unscoped npm packages (mailchimp-marketing and mailchimp_transactional) that were unclaimed on npmjs, enabling dependency confusion. The researchers published a claim for mailchimp-marketing, added a webhook, and observed significant usage (72,389 hits and roughly 500–1000 webhook triggers per week), demonstrating that an attacker could deliver remote code execution, malware, or ransomware; they recommend updating documentation to use scoped package names (e.g., @mailchimp/mailchimp_marketing).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
