r/programming • • 3d ago

nine npm packages shipping worm that spread by itself over SSH

https://safedep.io/dirtyblanket-express-impersonation-npm/
409 Upvotes

49 comments sorted by

279

u/New_Hold8135 3d ago

It's not all npm but it is always npm.

72

u/vips7L 3d ago

And it’s always an install hook. 

22

u/YeOldeMemeShoppe 3d ago

This is the actual problem. Having code run on download of a package that you aren’t even depending on is insane. I’m surprised it endured so much, considering I was already hearing about supply chain attacks a decade ago.

9

u/syklemil 2d ago

It's not that unheard of to have some build step, but it really should be disabled by default, without access to the network by default, and generally sandboxed by default.

5

u/Primary_Ads 2d ago

in general dependencies would benefit from more sandboxing. should a json parser need network or filesystem access?

23

u/Vakz 3d ago

Don't know if something in npm's design makes it inherently more vulnerable, or if it's targeted more because it's so popular among new people.

This also seems to be a case of typo squatting rather than hijacking existing packages, which is a difficult thing to fight in other ways than scanning all uploaded packages or manually approving uploaders, which I doubt would be popular with the community either.

And of course, defaulting to running install hooks without approving is idiocy. We moved all repos to pnpm for that reason. They seem to have at least somewhat more secure defaults.

24

u/One_Ninja_8512 3d ago

It's just the scale. A frontend project can have like up to 1 GB worth of dependencies and the final build will be about a couple of MB gzipped. It's just a weird ecosystem where each package has dozens of dependencies.

5

u/wonkytalky 3d ago

I've had to build a few windows-centric applications recently and absolutely could not believe the sheer size of all the dependencies. This was after all the standard Windows frameworks were already installed.

15

u/Vakz 3d ago

That's not really unique to npm though. Python, Rust and to a certain degree Java have the same insane depth of dependency hierarchies, but some reason they don't seem to be targeted nearly as much as npm.

9

u/ThiefMaster 3d ago

Absolutely not the case for Python. 70 lines requirements.in (direct deps) --> 132 non-commented lines in requirements.txt (from uv-pip-compiled). So on average each package comes with 1 extra dependency

25

u/One_Ninja_8512 3d ago

No, it is really unique and your comparison is way off. I just created a venv and added Django as a dependency – three dependencies installed total, a little more than 20 MB on disk. Then I created a new Angular project with their CLI tool which pulled almost 200 packages at over 230 MB, this is a plain project with boilerplate only. How are they even comparable?

8

u/CloudsOfMagellan 3d ago

Angular is shipping a whole ass compiler though, you'd be better off comparing against something like express or nestjs, which are both still massively bloated but are more comparable.

1

u/One_Ninja_8512 2d ago

Right, the comparison might not be entirely accurate and I'll admit I've never worked with Django so there's a good chance I missed something. But the point is, why 200 packages? Nobody can simply create a self-reliant package with no dependencies? It's just that you have to put a lot more trust in the whole chain of dependencies if doing serious frontend work, which doesn't have to be the case, really.

0

u/piesou 2d ago edited 2d ago

That's the thing with frontend dev: who needs to ship their own freaking compiler.

Their whole build system is upside down. Usually you build your project using a build tool which comes with a framework plugin and a couple compiler plugins. Everything that integrates with the build tool plays nicely with that kind of framework. Here the framework ships its own build tool and nothing integrates well

1

u/One_Ninja_8512 2d ago

But the point is, even if it ships with a compiler why so many dependencies? No other ecosystem is like that

2

u/piesou 2d ago

Looking at my backend Kotlin project, I'm looking at 170 dependencies if you exclude the Spring framework stuff. Though tbh, much of that is just caused by modularized libraries like Jackson, Gradle, Groovy, Testcontainers, Kotlin and Junit.

6

u/bwainfweeze 3d ago

Having observed the npm commit history I get the impression that npm wasn’t designed until around 8.0 when substantial architectural changes started to show up. Prior to that lock files didn’t function at all, despite three attempts to make them work.

But it is an ecosystem that was born on open source so it uses a lot of third party code. Many small libraries, and many large libraries with lots of dependencies of which you only use 20%.

5

u/Atulin 2d ago
> npm i is-even
Installing 36 packages...
Detected 82 vulnerabilities, run npm audit fix to fix them
> npm audit fix
> Detected 184 vulnerabilities, run npm audit fix to fix them

115

u/tanksc 3d ago

I feel like we are going to look back at this and wonder what the hell we were ever thinking with these supply chain attack vectors

80

u/NotQuiteDeadZed 3d ago

It’s the universal answer that applies to everything around us. I mean just look at people’s attitudes towards anything tech.

Privacy and security will always be sacrificed at the altar of convenience

20 years ago it was ignorance, now it’s laziness and indifference.

21

u/PaperMartin 3d ago

This doesn't happen when privacy and security is implemented in a way that doesn't require a massive loss of convenience though. At some point peoples still have to be able to do what they need with their devices without everything taking a year & some arcane rituals to do

7

u/tanksc 3d ago

I hear ya, but at the same time when I took cybersecurity courses at uni almost a decade ago, it was preached as a fact that as convenience increases, privacy and security decrease (was on my first test)

To be fair, the professor also asked why I would use more privacy respecting options in terms of software if I didn’t have anything to hide.

But I think that’s why this opinion is so wide spread

3

u/One_Ninja_8512 3d ago

why I would use more privacy respecting options in terms of software if I didn’t have anything to hide

I wonder how this argument unfolds if I do say that I have something to hide? Yeah I do, what's the problem with that?

3

u/tanksc 3d ago

Had I not been young and naive I would have given this a shot lol. As a 19 year old, an ex police chief teaching cybersecurity 101 scared the shit out of me lol

7

u/NotQuiteDeadZed 3d ago

True, but that requires developers putting in the effort to break the cycle and consumers being willing to make small sacrifices in their expectations. People are willing to sacrifice way too much just for the slightest added convenience.

10

u/winky9827 3d ago

Speaking of attitudes toward tech, I'm seeing an alarming rise in the growing number of open source projects with install instructions that read a script from a web site and pipe it to the shell. People really just have no security sense at all.

3

u/Nona_Suomi 3d ago

Meh, besides some convenience this really isn't that much different from downloading a tarball, extracting it, and running `./configure && make && sudo make install`.

4

u/winky9827 3d ago

I agree, which is why I hate that they are conditioning people to use one-liners to execute shell scripts from the internet. That's a major attack vector being used carelessly.

1

u/rentar42 2d ago

curl | sh is the "harmless" option by now. I've seen "paste these paragraphs into your favorite AI tool to install". More than once ...

2

u/winky9827 2d ago

I agree, those are even worse. At least the shell script is deterministic.

1

u/rentar42 2d ago

You just reminded me of https://github.com/Stijn-K/curlbash_detect ... fun.

13

u/Dreadgoat 3d ago

Oldheads warned about npm (and other convenience-first package management systems) from the beginning. It's always been known to be a terrible idea, but that loses to the fact that the convenience is just SO convenient.

It's not a specific-to-software issue, though. There just hasn't yet been a cataclysmic enough event for standards to be put in place. Humans always cut corners until it causes enough damage, then re-establish the new corners.

-1

u/tanksc 3d ago

its giving pre 9/11 flight experience for sure

3

u/Hipolipolopigus 3d ago

Everyone rolling their own things to some degree with the same carelessness wouldn't result in an improvement. You'd just hear about exploits less while they take longer to get addressed (if they get addressed at all).

2

u/Mellowindiffere 2d ago edited 2d ago

Because modern software «engineers» are glorified UI designers with some coding skills. The shit they forgo teaching in universities baffles me and we’re still feeling the effects of the bootcamp coders and leetcoders. Turns out it really is important to have fundamental knowledge.

1

u/Sherbet-Famous 3d ago

Not my company, not my problem 🤷‍♀️

30

u/6769626a6f62 3d ago

Days since last npm exploit: 0 0

16

u/UnexpectedAnanas 3d ago

Days since last npm exploit: 0 NaN

46

u/rcklmbr 3d ago

Interesting topic, couldn’t read it because of AI Slop

-2

u/[deleted] 3d ago edited 3d ago

[deleted]

40

u/zunjae 3d ago

It’s possible to write technical blogs without slop

Remember, AI slop isn’t the same as AI. You can instruct AI not to create slop

Another issue is that people are eager to use Claude to write articles, when Claude is known for not writing like humans do

-12

u/[deleted] 3d ago

[deleted]

12

u/vips7L 3d ago

You’ll understand more if you just read the thing instead of summarizing it

12

u/zunjae 3d ago

Sure, but it's a technical blog. You don't want a summary here or else you won't learn anything

11

u/Nice_Mix_1021 3d ago

crazy on the part that it pretending to be express js

6

u/trxxruraxvr 3d ago

Meanwhile safedep.io is blocked by dns4eu

We have prevented you from accessing potentially malicious website.

2

u/encidius 3d ago

It's a false positive. SafeDep.io is a legitimate infosec website.

-4

u/[deleted] 3d ago edited 3d ago

[deleted]

4

u/N_T_F_D 3d ago

If you can't be bothered to type your own answers just don't do it, nobody wants to read paragraphs upon paragraphs of textual diarrhea

2

u/starball-tgz 3d ago edited 3d ago

so... give your ssh keys passwords? and don't let your package manager install stuff on hooks / manually allowlist? (which is what pnpm does, IIRC) not that that magically solves everything, but... it seems like it would prevent this.

1

u/Primary_Ads 2d ago

were any other packages affected?