Account Takeover 2021 Incident #2 CVE-2021-4229

ua-parser-js hijack

Estimated Financial Impact
Tens of millions
Blast Radius
8M weekly downloads; Facebook, Amazon, Microsoft, Google

What Happened

Maintainer Faisal Salman's npm account was hijacked (offered for $20K on a Russian forum two weeks prior). Malicious versions installed an XMRig cryptominer and DanaBot credential-stealing trojan. The package had ~8M weekly downloads and ~1B lifetime downloads; companies affected included Facebook, Amazon, Microsoft, and Google. CISA issued an advisory.

Sources: Faisal Salman GitHub issue · Truesec incident response

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTS

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Caught Nexus Firewall blocks known-malicious packages at ingestion
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← event-stream / flatmap-stream eslint-scope →