Account Takeover 2018 Incident #3

eslint-scope

Estimated Financial Impact
$500K-2M
Blast Radius
2M weekly downloads; Babel, Webpack; 4500 tokens exposed

What Happened

An ESLint maintainer's npm account was compromised via credential stuffing (password reused, no 2FA). A malicious postinstall script in eslint-scope@3.7.2 exfiltrated .npmrc auth tokens to pastebin.com, designed as a worm to steal tokens for further package compromises. Approximately 4,500 accounts had tokens potentially exposed; npm revoked ALL tokens issued before the incident.

Sources: ESLint postmortem · Microsoft Azure DevOps response · NodeSource observer account

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTS

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Caught Nexus Firewall blocks known-malicious packages at ingestion
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← ua-parser-js hijack coa and rc packages →