All vulnerabilities
CRITICALSupply chainexploited in the wildcurated

NPM-UA-PARSER-JS-2021

npm · ua-parser-js

Summary

On 22 October 2021, attackers hijacked the npm account of the developer behind ua-parser-js, a small library downloaded 6 to 8 million times a week, and published versions that installed a cryptominer and a password-stealing trojan on every machine that updated. The malicious versions were live for only about four hours, but a library that popular reaches an enormous blast radius fast, because it is bundled, transitively, into a huge slice of the JavaScript world. It is a textbook reminder that the security of your app is the security of every maintainer in your dependency tree, including the small, single-author ones.

How it happened

ua-parser-js does something unglamorous and ubiquitous: it reads browser user-agent strings, and it was maintained by one person. Attackers compromised that maintainer's npm account, an account takeover through stolen credentials, and used it to publish three malicious versions (0.7.29, 0.8.0, and 1.0.0).

Each one carried a preinstall script, code that npm runs automatically during npm install. That script dropped binaries that ran an XMRig cryptominer on Linux and Windows and a password-stealing trojan (a DanaBot variant) on Windows. In other words, simply installing or updating the dependency was enough to run the backdoor; no other action was required. It is a supply-chain attack through a hijacked maintainer account, a close cousin of the event-stream takeover, but achieved by stealing the account rather than being handed it.

The damage

The malicious versions were live for about four hours. That sounds brief, but ua-parser-js is a transitive dependency of countless projects, so anyone who happened to run npm install on an affected project during that window was compromised. The guidance was unambiguous: update to the clean versions and treat any affected Windows machine as fully compromised, rotating every credential on it, because a password-stealer ran (Linux hosts ran only the XMRig miner, which even skipped machines it geolocated to Russia, Ukraine, Belarus, or Kazakhstan). The maintainer himself was a victim of the account takeover, and noticed it only when his inbox was suddenly flooded with signup spam; the incident became one of npm's strongest arguments for mandatory two-factor authentication.

Why ua-parser still matters

ua-parser is the maintainer-account-takeover lesson. A single developer's npm credentials are a skeleton key to millions of machines, and install scripts (preinstall and postinstall) run arbitrary code on every npm install, a giant and under-appreciated attack surface. The defences are concrete: require two-factor authentication on every npm maintainer and publisher account, the direct fix here; pin dependencies with a lockfile and review updates rather than auto-pulling the latest; run installs with scripts disabled where feasible, and in CI use isolated, least-privilege build environments so a malicious install script cannot reach your secrets; and monitor for unexpected new releases of the packages you depend on.

How to fix it

  • Pin to or upgrade past the clean versions (0.7.30, 0.8.1, 1.0.1) and rebuild from a clean lockfile.
  • Treat any Windows machine that installed a malicious version as fully compromised and rotate every credential it held, since a password-stealer ran; rebuild Linux hosts that ran the miner.
  • Audit install (preinstall and postinstall) scripts across your dependency tree and disable them where you can.

How to avoid it

  • Require 2FA on every npm maintainer and publisher account; account takeover was the entire attack.
  • Pin dependencies with a lockfile and review updates rather than auto-pulling the latest; a popular transitive package can be poisoned for hours before anyone notices.
  • Run installs with scripts disabled where feasible, and use isolated, least-privilege CI build environments so a malicious install script cannot reach your secrets.
  • Monitor for unexpected new releases of your critical dependencies and pull from a vetted internal registry mirror.

References

Related vulnerabilities

All Supply chain →