The world’s largest open-source registry, node package manager (npm), has been hit by another fast-moving malware attack, this time targeting the widely-used AntV enterprise data visualization tool.
Unlike last week’s high-profile npm attack , the account in question, atool ([email protected]), which publishes the timeago.js JavaScript library, had rights to a large catalog of packages, including popular tools such as size-sensor (4.2 million downloads per month), echarts-for-react (3.8 million), @antv/scale (2.2 million), and timeago.js (1.15 million).
This privilege level allowed the attacker to publish at least 637 malicious versions across 317 different npm packages in a single 22-minute burst. This resulted in the compromise of a big chunk of Alibaba’s AntV namespace, a growing platform across Asia, the US, and Europe used to build dashboards, user interfaces, and interactive applications.
Attacks on the npm supply chain this year plot a challenging trend, , the source code for which was recently briefly released to other criminals on GitHub.
Its purpose is to steal npm and GitHub tokens, as well as credentials from 130 file paths, including multiple cloud platforms, Kubernetes, Docker, Hashicorp, password vaults, SSH keys, and Bitcoin wallets.
For unknown reasons, the attackers then use stolen CI/CD tokens to store exfiltrated data in public GitHub repositories themed on the science fiction novel Dune, which, within hours of this attack, grew to 2,500 in number. Each repository description contains the string “niagA oG eW ereH :duluH-iahS” (“Shai-Hulud: Here We Go Again” backwards).
In theory, the malware is also capable of persistence via a Python-based backdoor installed at ~/.local/share/kitty/cat.py, although , which allows the malware to be stealthily reinstated with full LLM privileges in case the infected npm packages have been removed.
Next steps
After the attack was detected, AntV’s maintainers issued the following as a .csv), although it’s safe to assume that if any version of the AntV library is in use, infection is a possibility.
Beyond that, recommended actions are to look for signs of compromise in CI/CD environments and repositories, and to rotate all credentials.
But the most important advice from experts is much simpler: strengthen defenses against future attacks targeting npm by improving monitoring and package verification.
This article originally appeared on InfoWorld.
SOCIAL SHARE CARD GENERATOR