Mô tả
Một vụ tấn công chuỗi cung ứng quan NPM có tên “Shai-Hulud” đã diễn ra vào sáng ngày 16/09. Cụ thể, thư viện @ctrl/tinycolor với trung bình 2.2 triệu lượt tải hàng tuần và một số package khác đã bị push một bản update đính kèm trojan. Khi được chạy mã độc sẽ quét filesystem bằng Regex/TruffleHog, để quét các key/env và dump process.env để lấy các thông tin về access token như Github, AWS, Azure, GCP,…
Phạm vi ảnh hưởng
- angulartics2@14.1.2
- ctrl/deluge@7.2.2
- ctrl/golang-template@1.4.3
- ctrl/magnet-link@4.0.4
- ctrl/ngx-codemirror@7.0.2
- ctrl/ngx-csv@6.0.2
- ctrl/ngx-emoji-mart@9.2.2
- ctrl/ngx-rightclick@4.0.2
- ctrl/qbittorrent@9.7.2
- ctrl/react-adsense@2.0.2
- ctrl/shared-torrent@6.3.2
- ctrl/tinycolor@4.1.1, @4.1.2
- ctrl/torrent-file@4.1.2
- ctrl/transmission@7.3.1
- ctrl/ts-base32@4.0.2
- encounter-playground@0.0.5
- json-rules-engine-simplified@0.2.4, 0.2.1
- koa2-swagger-ui@5.11.2, 5.11.1
- nativescript-community/gesturehandler@2.0.35
- nativescript-community/sentry 4.6.43
- nativescript-community/text@1.6.13
- nativescript-community/ui-collectionview@6.0.6
- nativescript-community/ui-drawer@0.1.30
- nativescript-community/ui-image@4.5.6
- nativescript-community/ui-material-bottomsheet@7.2.72
- nativescript-community/ui-material-core@7.2.76
- nativescript-community/ui-material-core-tabs@7.2.76
- ngx-color@10.0.2
- ngx-toastr@19.0.2
- ngx-trend@8.0.1
- react-complaint-image@0.0.35
- react-jsonschema-form-conditionals@0.3.21
- react-jsonschema-form-extras@1.0.4
- rxnt-authentication@0.0.6
- rxnt-healthchecks-nestjs@1.0.5
- rxnt-kue@1.0.7
- swc-plugin-component-annotate@1.9.2
- ts-gaussian@3.0.6
- Có thể bao gồm cả các package khác có sử dụng đến các package bị ảnh hưởng nêu trên.
Biện pháp khắc phục
- Kiểm tra các dependency của dự án, package trong hệ thống nếu có tồn tại phiên bản bị lây nhiễm.
- Gỡ cài đặt hoặc ghim về các phiên bản an toàn cuối cùng trước khi có bản vá.
- Thay đổi các npm token và thông tin xác thực khác nếu các package bị ảnh hưởng đã được cài trên máy có quyền publish.
Nguồn tham khảo
- https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages
- https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised