A Popular npm Library Compromised in a Supply Chain Attack
ID: 0e835f11-ac9a-5771-8892-373ec1cfa07d
STIX ID: report--0e835f11-ac9a-5771-8892-373ec1cfa07d
Feed Name: Aqua Security Blog
In late October 2021 the popular npm library ua-parser-js was compromised after an attacker took over the maintainer's account and published malicious versions that run preinstall scripts to fetch a cryptominer (Linux ELF or Windows batch) and a Windows password-stealing DLL (create.dll); the compromised versions had millions of downloads and were patched within hours. The report provides indicators (file names and MD5 hashes), notes similarities to prior malicious npm packages, outlines detection and remediation steps (scan for listed binaries, rotate credentials, update packages), and recommends supply-chain security best practices and runtime detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
