All vulnerabilities
CRITICALSupply chainexploited in the wild

NPM-UA-PARSER-JS-2021

npm · ua-parser-js

Summary

On October 22, 2021, an attacker hijacked the npm account of ua-parser-js maintainer Faisal Salman and published malicious versions 0.7.29, 0.8.0 and 1.0.0 of the library, which had 6-8 million weekly downloads. A preinstall script dropped binaries (jsextension on Linux, jsextension.exe on Windows) that ran an XMRig cryptominer on Linux and Windows and a password-stealing trojan on Windows. The malicious versions were live for roughly four hours; users were urged to update to 0.7.30, 0.8.1 and 1.0.1 and treat affected machines as fully compromised.

References

Related vulnerabilities

All Supply chain →