Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

CVE-2017-16074

npm · crossenv (+ ~37 typosquat packages)

Résumé

In late July/August 2017, a user named 'hacktask' published around 37 typosquatting packages on npm with names mimicking popular libraries, the most notable being 'crossenv' (impersonating cross-env). The package replicated the legitimate functionality but added an install-time snippet that harvested all environment variables, often containing tokens, keys and credentials, and exfiltrated them to npm.hacktask.net. crossenv was tracked as CVE-2017-16074; actual installs were limited (estimated under ~50) and npm removed roughly 40 packages.

Références