THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalnpm·credential theft·osv

Malicious code in share-anything-cli (npm)

share-anything-cli

Risk score

92

AI summary

Indexed incident for share-anything-cli (npm).

Description


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (290f9dadaf589349dd8a7c641450aca713a6ead63b2ba685c15e4e6a37ab3b07)

The package's package.json declares a postinstall lifecycle hook ("postinstall": "node install.js") that runs install.js automatically on npm install. install.js requires child_process and https, gathers host data (process.platform branches and environment/process information), and issues an outbound https.get(...) call. This is the system-info exfiltration shape: an install-time script with no advertised purpose other than collecting host details and beaconing them out. Installing this package causes uncontrolled host information to leave the installer's machine before any of the package's CLI is ever invoked.

Technical details

Affected versions

<function fixed() { [native code] }

Indicators

  • affected_version<function fixed() { [native code] }75%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents