All vulnerabilities
CRITICALSupply chainexploited in the wild

NPM-COA-RC-2021

npm · coa, rc

Summary

On November 4, 2021, attackers hijacked the npm accounts behind the popular packages coa (~9 million weekly downloads, used widely in React tooling) and rc (~14 million weekly downloads), publishing malicious versions (coa 2.0.3/2.0.4/2.1.1/2.1.3/3.0.1/3.1.3 and rc 1.2.9/1.3.9/2.3.9). A postinstall script fetched OS-specific scripts that installed a DLL password-stealing trojan (likely DanaBot). The malware was the same family seen in the ua-parser-js compromise weeks earlier, indicating a common threat actor.

References

Related vulnerabilities

All Supply chain →