Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MAL-2024-7418 is not malicious but just sending a ping to a host #568

Closed
Shivang0 opened this issue Jul 6, 2024 · 1 comment
Closed

Comments

@Shivang0
Copy link

Shivang0 commented Jul 6, 2024

MAL-2024-7418 is not malicious but just sending a ping to a host

@calebbrown
Copy link
Contributor

While not strictly malicious, this package does fall into the what is acceptable for this repository (see changes proposed in #381).

  • The behaviour exfiltrates the hostname to a domain used by the interactsh tool. Hostname is sensitive enough to launch further targeted attacks.
  • The name and description of the package do not indicate this behavior, and in-fact masquerade as a react related package - likely indicating a dependency confusion attempt.
  • The versions of react-devtools-fusebox in question have been removed from NPM.
  • Finally, the original version of the package v2.0.1 (not included in the advisory) exfiltrated further identifying data (including username, and homedir).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants