Account Takeover 2021 Incident #4

coa and rc packages

Estimated Financial Impact
$5-15M
Blast Radius
23M combined weekly downloads; React pipelines globally

What Happened

The same threat actor (UNC3379) hijacked both coa and rc via compromised npm accounts, injecting obfuscated TypeScript post-install scripts that downloaded the DanaBot banking trojan. Neither package had been updated in 3 years before the malicious release. Combined weekly downloads were ~23M; the attack broke React build pipelines globally.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_INSTALL_SCRIPTSPACKAGE_STALE_RELEASE

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Caught Nexus Firewall blocks known-malicious packages at ingestion
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← eslint-scope rest-client gem →