Threat Alert: Private npm Packages Disclosed via Timing Attacks
ID: 9cfb449c-dcf3-5471-aacb-5a5e0b23a06c
STIX ID: report--9cfb449c-dcf3-5471-aacb-5a5e0b23a06c
Feed Name: Aqua Security Blog
Aqua Nautilus discovered that npm's API architecture and caching behavior permit a timing attack where unauthenticated GET requests to scoped package endpoints return 404 responses with measurably different latencies for existing versus non-existing private packages; by sending multiple requests and analyzing response times attackers can enumerate private package names, enabling subsequent supply-chain attacks such as typosquatting or creating malicious public packages to masquerade as private ones. The blog provides test methodology, measured timings, mitigation recommendations (inventory, lookalike detection, placeholder public packages), and notes GitHub responded that the behavior is an architectural limitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
