A math solver leads to encrypted code in npm packages. Follow the loader, the trigger matrix that unlocks it, the remote access payload, and the full indicators.
43 comments
Turns out the second stage is completely broken, which is even more odd..
https://research.veryserious.systems/lusolve-and-you-shall-r...
My guess is that it's crypto related but of course it could be anything.
Aka If someone from the outside can make your equipment emit X internally, they can target X in some way.
Someone thought I was joking when I said I always check JSR before NPM now, because I trust ESM so much more than CommonJS.
(ETA: Even/especially in minified code. Something like `var r = require` is rather common in Code Golfing/minifying CommonJS so grepping all uses of require both static and dynamic is also complicated by nicknames. But ESM doesn't minify static import ever and yeah dynamic import might be minified, but that still means it sticks out as a sore thumb if it exists at all even in minified shapes. Especially in minified shapes because that often means it is used multiple times for a minifier to decide that minifying it is worth the tax of declaring the minified nickname.)
I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain
But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain
Read the full thread on Hacker News →
Related stories
- Lobsters · 86 points · about 1 year ago
- Show HN: Mathy – Build Math Automaticitymathy.gameHacker News · 1 points · 9 days ago
- Hacker News · 8 points · 6 days ago
- Hacker News · 4 points · 6 days ago
- Hacker News · 14 points · 8 days ago
- DEV Community · 14 points · 11 days ago