HomeSecurityMalicious code removed from PureScript npm installer

Malicious code removed from PureScript npm installer

installer

Another JavaScript in PureScript's npm installer has been compromised, forcing administrators to review their software to clean up the malicious code.

After a week of reports of unexpected behavior, PureScript software developer Harry Garrood reported the issue on account .

The installer, which you use by typing npm i -g purescript from the command, is designed to install PureScript, a programming language that compiles to JavaScript, on the user's system using the npm command-line interface. It is used about 2,000 times a week.

A Japanese developer, Shinnosuke Watanabe (@shinnn), created the installer, according to Garood. administrators had a disagreement with Watanabe over the maintenance of the installer and asked him to move the project under their control.

The malicious code was introduced into the npm packages load-from-cwd-or-npm and rate-map at different times, to evade the recent revision of the PureScript installer, but not the previous versions published by Watanabe.

"As far as we know, the sole purpose of the malicious code was to undermine the PureScript npm installer to prevent it from running successfully," Garood said.

Earlier this month, a Ruby gem package was hijacked. And in June, a vulnerability in an npm package was used to steal cryptocurrency, while a similar incident occurred in November.

Garrood hints that Watanabe is responsible for the vulnerability, without directly blaming him. However, he claims that Watanabe deleted a GitHub on July 9 by developer Jolse Maginnis indicating that his load-from-cwd-or-npm affects the installer.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS