paint-brush
NPM shrinkwrap allows remote code executionby@deian
1,091 reads
1,091 reads

NPM shrinkwrap allows remote code execution

by Deian Stefan6mDecember 12th, 2016
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

If you install an npm package (or any packages it may depend on) that has a shrinkwrap file (<code class="markup--code markup--p-code">npm-shrinkwrap.json</code>) with a HTTP registry URL, a local <a href="https://hackernoon.com/tagged/network" target="_blank">network</a> attacker (MITM) can execute malicious code on your machine.

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - NPM shrinkwrap allows remote code execution
Deian Stefan HackerNoon profile picture
Deian Stefan

Deian Stefan

@deian

L O A D I N G
. . . comments & more!

About Author

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Helperbyte