Yeeks. Not good.
(sudo) gem update --system ASAP
Yeeks. Not good.
(sudo) gem update --system ASAP
AFAICS this is the relevant line: https://github.com/rubygems/rubygems/blob/master/lib/rubygem...
Edit: Or, if you want to get a little more creative, have your gem include a plugin to rubygems itself, similar to what https://github.com/rvm/executable-hooks does.
So while this is bad, I don't think it's that bad -- a malicious gem could always mess you up. Still update!
But even if: most systems today probably only run that one service, and the application server can rwx pretty much everything of interest because that's its job, right?
10 years or so ago you'd often see some company's server running apache as well as a mail server, the internal document repository and the financial systems. In that sort of setup, it's important to (try to) keep these systems isolated from each other. But today, all that root access would give you is the ability to read a few more Ubuntu man pages.
The file overwrite and the ANSI sequence vulnerabilities are extra attack vectors. The main one has anyways been the code itself and its vetting process. This for Ruby gems and for any other open and closed source piece of code we run on our machines, starting from the processor(s) microcode.
Eh, I don't know about that. I don't think most application servers are running as root, and I'm pretty sure it's considered bad practice to run them as root, no?
But yeah, they still need to have enough privs to do their jobs, which will be a lot of privs. But you still don't go from that to "might as well just run as root then".
The problem here is that you don't even have to get directly attacked to be affected.
Granted that was just data collection, but the outcome could be incredibly worse if a combo of popular but bad code and a little bit of money.
After this got uncovered, Duo published a blog post where they scanned for and found several others malicious packages:
https://duo.com/blog/hunting-malicious-npm-packages
The last one they talk about worms itself by adding itself to any packages authored on the computer it's installed on.
These issues are not unique to npm.