Supply-chain threat intelligence

Incident detail

criticalnpm·credential theft·osv

Malicious code in atlasora-shared (npm)

atlasora-shared

Risk score

92

AI summary

Indexed incident for atlasora-shared (npm).

Description

package.json declares "postinstall": "node install.js", causing install.js to run automatically on npm install. install.js requires https, fs, os, and child_process, collects host identifiers via os.hostname() and os.userInfo(), executes shell commands via execSync(...), probes filesystem paths with fs.existsSync(...), and POSTs the collected data to a remote endpoint via https.request(...). This is the canonical install-time system-information exfiltration pattern: identifying data is gathered from the installer's machine and beaconed outbound on every install, with no documented purpose tied to the package's stated function. Installing this package automatically leaks host and user information to an external destination.

Technical details

Affected versions

=1.0.0

Indicators

  • affected version=1.0.075%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents