Fake VS Code Extension on NPM Spreads Multi-Stage Malware
mend.io
mend.io
The article describes a vscode extension on vscode marketplace squatting the name of an existing extension, from how it’s worded it sounds like the extension directly contains the malware rather than being compromised through a dependency, what does it have to do with npm?
1. 212.bat.exe; 1/61; https://www.virustotal.com/gui/file/2c76036ec0869f6b41bd8f7c...
2. haha.msi; 2/61; https://www.virustotal.com/gui/file/1b2d956e3eded3e7220e3ff6...
3. MLANG.dll; 15/61; https://www.virustotal.com/gui/file/a8e7f45d67b50948929adf35...
or if you focus on network/ips/perimeter detections:
4. web.winserve[.]ru; 1/94; https://www.virustotal.com/gui/domain/web.winserve.ru
5. scare[.]su; 3/94; https://www.virustotal.com/gui/domain/scare.su
PSA: Never run untrusted code on important machines. This might mean forbidding the use of third-party extensions for common applications until they are audited, something Microsoft clearly isn't doing.
No need for hyperbolics, just say you don't know.
The built in Windows Firewall does this. No need to pay for a 3rd party magic app.
Laud praise on Little Snitch all you want but Windows could quietly do this out of the box for two decades.
25 years ago we used ZoneAlarm and a variety of other tools.
I'm not a macOS user anymore, but when I was, Little Snitch did more than just block/allow all connections a program makes. You get a popup/window for each connection attempt, and can whitelist the process, domain, specific address, port and more.
Is this really how Windows Firewall works? Because I've used Windows for more than two decades, and I only remember a boolean "allow/disallow" based on the program itself, when it tries to make a connection, then you see nothing else unless you manually go and dig into the configuration/rules. Have I been missing out on something?
In Windows Defender Firewall settings right click Outbound Rules, click New Rule. Choose the type of rule (Program, Port, Predefined, Custom). You can apply the rule to a program / set of programs, a service or globally. You can apply it by protocol, port, IP, specific network interfaces etc. The only thing I can't find that was mentioned in GP is rules based on domain/address - I'm not sure if this is a limitation of the firewall or I'm just too dumb to find it.
I've never been fully satisfied with software firewalls, but WFC comes close.
Windows firewall does not appear to have similar features. A vscode extension connecting to a host I run is okay, connecting to a random domain is not okay and I don't see anything at all in windows firewall to notify me about individual connections. Please advise me on where this functionality is if I'm just missing it.
And there's a lot about little snitch that I actively dislike, but its features are extremely useful. I'd love to have those on windows as well.
As others have linked me similar software, I will explore those.
It doesn't have "allow but notify," if that's what you're looking for.
With little snitch, I use "notify and I select allow or deny". And it works for ip addresses (4 and 6) as well as domains. It's a powerful system, but if I can get similar with domain allowlisting, that would be a worthwhile improvement.
Given that language package managers are intentionally open to the public, "someone uploaded malware to NPM" is not itself an interesting story. What would be interesting is whether a particular typosquatting campaign was effective, given that most appear to be caught before download counts leave "background noise" levels.
Or as another framing: malware on an unrestricted index does not matter if nobody actually downloads it. What matters (and is interesting) is when the attacker manages to get nontrivial numbers of downloads to their package.
I am an avid vscode advocate, but it is incredibly invasive and security ignorant.
https://github.com/legobeat/l7-devenv/pull/153
This works for me (which I do run in VMs also, yes). A key thing is some secrets like GH token and signing keys are not available even for the IDE and code in the environment requiring them. Like a poor-mans HSM, made for dev, kinda. Also LLM assistant gets access to exactly what it needs. No more, No Less.
You can have your cake and eat it too.
If you go for a VM, why involved containers at all? What additional security you get from layering containers on top of VMs, compared to just straight up use a VM without containers?
In reality, if it's target malware, it will, and if it's a mass-spray like a simple VSCode extension, it won't have either. (Nigerian Prince theory: You don't want to deal with the security-conscious people for a mass-attack)
In the setup I linked, separation is more fine-grained. Ephemeral container for each cargo/nodejs/python/go/gcc process. The IDE is in a separate container from its own language servers, and from the shell, which is separate from both the X server and the terminal window, the ssh agent, etc. Only relevant directories are shared. This runs my devenv with vscode fine on a 16GB RAM 8c machine.
You'd need like 1T RAM and over 9000 cores to have that run smoothly with real VMs ;)
Basically containers can give you far more domains (with better performance and weaker isolation) on the same host.
The other upside is that the entire containerized setup can be run as unprivileged user. So an escape means they are still nerfed local user. A typical VM escape would have much shorter path to local root.
When people delegate their brains to others, their own judgment naturally deteriorates and it makes them much easier to fool.
What? That simply is not true unless you mean "good" as in "good in spreading malware". lol
Which is a help for spreading both good code and malware.
Other than that, I don't think there's a difference. When I write node projects, I tend to minimize dependencies, but I've seen PR comments saying "you know you could just get a package to do that".
Do you have some statistics on that, or do you just feel that way?
Not in anywhere I've worked for the past ~decade...
Just mentioning these because they are trendy.
Regarding the general issue, it can happen in any language with package management.
Its not reasonable to just yell js sucks because I’ve seen it in bunch of places by now.
A thought as old as thoughts about thoughts are, almost:
> For this invention will produce forgetfulness in the minds of those who learn to use it, because they will not practice their memory. Their trust in writing, produced by external characters which are no part of themselves, will discourage the use of their own memory within them. You have invented an elixir not of memory, but of reminding; and you offer your pupils the appearance of wisdom, not true wisdom, for they will read many things without instruction and will therefore seem to know many things, when they are for the most part ignorant and hard to get along with, since they are not wise, but only appear wise.
The quote above is about books, from Plato's dialogue Phaedrus 14 (370-360 BCE). You by any chance feel the same about books as you feel about reusable JavaScript modules published on npm?
Nothing is black nor white but npm brought its fair share of dumb shit: https://en.m.wikipedia.org/wiki/Npm_left-pad_incident
I mean, it is fairly similar to what parent actually wrote, isn't it a relevant quote in the context? You're not actually arguing for one way or another, but simply because you've seen the quote multiple times before, it doesn't apply, or what are you trying to say?
How is the left_pad incident related to developers becoming easier to fool?
Sure. So too have books. In that instance, does the blame lie on the advent of books, or to the reader too naive to tell the difference?
On the balance, writing has been a net positive. Probably. Plato wasn't wrong; he could (or would) not anticipate the upsides.
If you do not believe that, then might I interest you in uncritically imbibing the succulent nectar of wisdom flowing from the Flat Earth Society?
I’m by no means agreeing with the quote, nor am I against reusing programming libraries carelessly; I just don’t see how the two are related.
> it has the same description as the original truffle extension: “Build, debug and deploy smart contracts on EVM-compatible blockchains.”
Because VSCode and npm are popular.
It’s not like Ruby gems are immune to this. They just aren’t as popular.
LLM-ass comment.
I dunno, Linux distros have a pretty good track record at the same problem, over multiple decades of evidence.
The difference is that they don't allow self-publication. Canonical and Red Hat et. al. work downstream of an active community of developers cross-attesting good software. So their problem becomes "This software is known to be good, let's package it!". So to get malware into the machines of users it's not enough to fool the users, you need to fool the packagers too. And it happens, but very rarely (c.f. the xzutils mess from last year).
Node and similar repositories thought they could short-circuit that process, and as has been extensively documented, it doesn't work because users are too lazy to authenticate their own software.
> the need for caution when installing VS Code extensions, especially those obtained from public package registries like npm.
I'm not aware of any way to install a VS Code extension through NPM. The article honestly just reads like the author knew that Mend does a lot of business selling NPM dependency scanning and that they're therefore expected to stuff it as a keyword for SEO.
The package uses javascript obfuscation for downloading the first stage of the malware, than it uses a heavily obfuscated batch file to conntinue into the second phase.
Lastly it leverages preconfigured ScreenConnect remote desktop installer to communicate with the compromised machine.
Back in the Sublime text days, it was easy. I think I had forgotten how complex I had made VS Code. Turns out, paying someone else $120/year to deal with that complexity in an IDE is a helluva good deal at your average developers hourly pay.
1: https://support.mozilla.org/en-US/kb/profile-manager-create-...
2: https://support.google.com/chrome/answer/2364824
3: https://addons.mozilla.org/en-US/firefox/addon/multi-account...
The DailyDev plugin only has access to "https://*.daily.dev/" and "https://*.dailynow.co/". It is also not required, you can just go to app.daily.dev yourself (I did not want to install the addon on my main PC)
Psa: reduce your installs of things from the internet
Don't get me wrong, I'm not saying one is better/worse than the other, but there are tradeoffs that not everyone is willing to make. I personally prefer the slower more intentional/reviewed option of package repositories like debian and arch, but things like npm/pypi/aur has their uses too.
Why obsess over that 0.01% when surrounded by dark age skiddies who haven't discovered germ theory yet, focus the message: "wash your hands!"
Which is a good thing. It's not like npm skiddies use this agile process to revolutionize the industry with AGI, they do left pad and a different framework every week.
All of this is proper of a foundation layer. So as a dev you find that the first dependencies to go are at the app layer, and all that is left are OS dependencies.
So