The problem appears to be in the vulnerable Electron development framework.The
Electron development framework for creating chat applications is a very popular framework among developers and supports a lot of projects. The Electron is based on JavaScript and Node.js and is used to create Skype, WhatsApp, Slack, and many other communication tools on the Internet.
However, according to researcher Pavel Tsakalidis, the Electron development framework poses a very serious threat to application security.

At BSides LV this week in Las Vegas, Tsakalidis presented the BEEMKA for decompressing Electron ASAR files, the code embedded in Electron JavaScript libraries, and built-in Chrome browser extensions.
It should be noted that the vulnerability discovered by the researcher does not exist in the applications themselves, but in the Electron development framework used to create them. However, with the help of the vulnerability, an attacker can very easily hide their malicious activity in legitimate processes.
See the Proof of Concept
To modify libraries and extensions, an attacker would first need to gain administrator privileges on Linux or MacOS systems. In the case of Windows, local access is sufficient.
By making changes to libraries and extensions, the attacker can create new “functions” that can access the file system, enable the webcam, and extract sensitive data (such as passwords) from the system, using the trusted applications feature.
In the video above, Tsakalidis demonstrates a PoC in Microsoft Visual Studio with a backdoor that sends user input to a remote website.
According to the researcher, he informed Electron about the vulnerability, but received no response while the problem still exists.
________________________
- Google Chrome Advanced Protection Program
- How to clean your keyboard once and for all
- Windows 10: see the last 10 copied items to the clipboard
