Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

NPM-ESLINT-SCOPE-2018

npm · eslint-scope, eslint-config-eslint

Résumé

On July 12, 2018, an attacker compromised an ESLint maintainer's npm account (the maintainer had reused their password and lacked 2FA) and published malicious versions eslint-scope@3.7.2 and eslint-config-eslint@5.0.2. On installation, the packages downloaded and executed code from pastebin.com that read the victim's .npmrc file and exfiltrated its npm publish tokens to the attacker, an attempt to self-propagate by stealing more publishing credentials. npm revoked all tokens issued before 2018-07-12 12:30 UTC in response.

Références

Vulnérabilités liées

Tout Supply chain →