I'm a bit confused... how did they get their updates pushed to a repo they didn't control?
I'm a bit confused... how did they get their updates pushed to a repo they didn't control?
They didn't update any part of cdnjs itself. Instead, they triggered cdnjs on their package.
Amusingly you can see the "hey-sven" library they added to test the fix: https://github.com/cdnjs/packages/pull/695
If you download the tarball directly, https://registry.npmjs.org/hey-sven/-/hey-sven-1.0.2.tgz, then tar -ztvf hey-sven-1.0.2.tgz, you can see
-rw-r--r-- 0 ryotak staff 204 Jun 2 16:21 package/package.json
-rw-r--r-- 0 ryotak wheel 10 Jun 2 16:21 ../../../../../../../../../../tmp/ryotak
-rw-r--r-- 0 ryotak wheel 10 Jun 2 16:22 ../../../../../../../../../../tmp/ryotak.sh
both which just have the contents "Retesting"
Because if he did that symlink should at least raised some eyebrows at least
from 2019/12/20 cloudflare blog post about cdnjs project: https://blog.cloudflare.com/an-update-on-cdnjs/
or maybe there's another exploit to publish a bad version of someone else's package to npm that is already approved to have new versions mirrored by cdnjs robots ( i have no evidence that this was done in this case, but an attacker might be able to do it. there's a lot of surface area to attack in build & release pipeline of 4000+ packages )