
Another JavaScript in PureScript's npm installer has been compromised, forcing administrators to review their software to clean up the malicious code.
After a week of reports of unexpected behavior, PureScript software developer Harry Garrood reported the issue on account .
The installer, which you use by typing npm i -g purescript from the command, is designed to install PureScript, a programming language that compiles to JavaScript, on the user's system using the npm command-line interface. It is used about 2,000 times a week.
A Japanese developer, Shinnosuke Watanabe (@shinnn), created the installer, according to Garood. administrators had a disagreement with Watanabe over the maintenance of the installer and asked him to move the project under their control.
The malicious code was introduced into the npm packages load-from-cwd-or-npm and rate-map at different times, to evade the recent revision of the PureScript installer, but not the previous versions published by Watanabe.
"As far as we know, the sole purpose of the malicious code was to undermine the PureScript npm installer to prevent it from running successfully," Garood said.
Earlier this month, a Ruby gem package was hijacked. And in June, a vulnerability in an npm package was used to steal cryptocurrency, while a similar incident occurred in November.
Garrood hints that Watanabe is responsible for the vulnerability, without directly blaming him. However, he claims that Watanabe deleted a GitHub on July 9 by developer Jolse Maginnis indicating that his load-from-cwd-or-npm affects the installer.
