Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Malware & Threats

Snyk Says ‘Malicious’ NPM Packages Part of Research Project

Apparently malicious NPM packages linked to Snyk raised some concerns, but the security firm clarified that it’s part of a research project.

Snyk malicious NPM packages

Several apparently malicious NPM packages linked to Snyk raised some concerns, but the developer security firm said they were part of a research project and suggested that there was no risk to anyone.

SourceCodeRed researcher Paul McCarty raised the alarm last week when he spotted the packages on the NPM Registry, warning that the packages were designed to collect data about the system and send it back to the attacker. 

McCarty’s analysis revealed that the NPM packages in question were deployed by someone from Snyk and the target was AI code editor Cursor. 

“Now, typically, when we see packages like this, they are attempting to perform a dependency confusion attack on a specific company. I don’t know if Cursor.com has a bug bounty program or a specific background,” McCarty explained. 

“The person who created these packages is probably hoping that Cursor employees accidentally install these public packages, which will send their data to the attacker-controlled web service,” he added.

The NPM packages raised some questions and concerns on social media, but Snyk assured everyone on Tuesday that the packages were not malicious.

Snyk told SecurityWeek in an emailed statement, which has also been posted in response to the social media posts, that the packages were released as part of a research project focusing on dependency confusion. 

“Snyk Research Labs regularly contributes back to the community with testing and research of common software packages,” said Snyk CTO Danny Allan. “This particular research into Cursor was not intended to be malicious and included Snyk Research Labs and the contact information of the researcher. We were very specifically looking at dependency confusion in some VS Code extensions. The packages would not be installed directly by a developer.”

Advertisement. Scroll to continue reading.

Allan added, “Snyk does follow a responsible disclosure policy and while no one picked this package up, had anyone done so, we would have immediately followed up with them.”

The packages have been removed from the NPM Registry. 

Malicious NPM packages have made many headlines in recent years so it’s not surprising that Snyk’s packages raised concerns. 

Someone claiming to be a developer at Cursor said the company got an apology from Snyk after the existence of the packages came to light, but described the security firm’s actions as “irresponsible”. 

Related: Microsoft DRM Hacking Raises Questions on Vulnerability Disclosures

Related: Prototype UEFI Bootkit is South Korean University Project; LogoFAIL Exploit Discovered

Related: Hundreds Download Malicious NPM Package Capable of Delivering Rootkit

Related: Dozens of Malicious NPM Packages Steal User, System Data

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Discover strategies for vendor selection, integration to minimize redundancies, and maximizing ROI from your cybersecurity investments. Gain actionable insights to ensure your stack is ready for tomorrow’s challenges.

Register

Dive into critical topics such as incident response, threat intelligence, and attack surface management. Learn how to align cyber resilience plans with business objectives to reduce potential impacts and secure your organization in an ever-evolving threat landscape.

Register

People on the Move

The US arm of networking giant TP-Link has appointed Adam Robertson as Director of Information and Security.

Cyber exposure management firm Armis has promoted Alex Mosher to President.

Software giant Atlassian has named David Cross as its new CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.