Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

The mysterious supply chain concern of string-width-cjs npm package

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
1,455
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

A potential supply chain attack was discovered when a developer noticed an unfamiliar syntax change to the package manifest of the cliui npm package. The proposed changes involved using an "npm:" prefix syntax, which is part of the npm package manager's aliasing feature. This feature allows custom resolution rules for packages and can be abused in cases like supporting ESM vs CJS. The developer employed lockfile-lint to examine the pull request and found suspicious behavior concerning malicious modules. Further investigation revealed that these suspicious packages existed on the public npm registry, had empty code repositories, were published anonymously without any associated personal information, and had a large number of dependents despite not doing anything. The developer concluded that this could be part of a supply chain security campaign or spam and abuse of public registries like npm and GitHub to mine for Tea tokens. It is recommended to adopt security practices while working with open-source software to ensure code safety.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.