65 points abhisek 1 hour ago 11 comments

j2kun 54 minutes ago | parent

Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?

zarzavat 49 minutes ago | parent

Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.

krackers 4 minutes ago | parent

Now I'm curious what the target was. Are there any notable classes of programs/problems where you'd do an LU decomposition of this specific matrix?

tranceylc 23 minutes ago | parent

I would assume it’s actually so they can allow it to spread before it gets activated. Then do something that affects the entire chain of package dependencies

coder-pm 5 minutes ago | parent

This matrix is not a condition, it’s a key. JSON.stringify with it’s data goes to the scrypt as a password and that creates an AES-256-GCM key. There is no if, every other input won’t decrypt. That’s why no one will get payload from the package without knowing the exact input.

fshafique 41 minutes ago | parent

Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?

I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain

But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain

nextzck 40 minutes ago | parent

Fascinating how intricate the target selection is on this

altairprime 37 minutes ago | parent

> We found a remote access implant hidden inside [email protected], an npm package that copies the popular mathjs library.

The NPM package not named in the clickbait-y post title is “mathmain@1.0.0”, for those who run into this particular site obstacle.

Safedep, if you’re reading this, perhaps you should reconsider having that site feature applied to your post — or if it’s something you enabled in, say, Cloudflare, perhaps file a support ticket noting that their email protection is hiding package version strings.

QuantumNomad_ 21 minutes ago | parent

Probably Cloudflare. For me it shows the package name rather than a redaction. But from memory, Cloudflare email protection redacts it that way in the HTML and then adds a little JS to put it back in which might also do some kind of check to see if it thinks you are a real user before unredacting it.

TZubiri 34 minutes ago | parent

My strategy of not using dependencies at all seems to be getting stronger everyday.

Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.

Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.

iLoveOncall 11 minutes ago | parent

Let us know in 2838 when you finish your first program, would love to check it out!