Why does mathmain need an encrypted loader?

(safedep.io)

65 points | by abhisek 1 hour ago

6 comments

  • altairprime 35 minutes ago
    > We found a remote access implant hidden inside [email protected], an npm package that copies the popular mathjs library.

    The NPM package not named in the clickbait-y post title is “[email protected]”, for those who run into this particular site obstacle.

    Safedep, if you’re reading this, perhaps you should reconsider having that site feature applied to your post — or if it’s something you enabled in, say, Cloudflare, perhaps file a support ticket noting that their email protection is hiding package version strings.

    • QuantumNomad_ 19 minutes ago
      Probably Cloudflare. For me it shows the package name rather than a redaction. But from memory, Cloudflare email protection redacts it that way in the HTML and then adds a little JS to put it back in which might also do some kind of check to see if it thinks you are a real user before unredacting it.
  • fshafique 39 minutes ago
    Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?

    I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain

    But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain

  • j2kun 51 minutes ago
    Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?
    • coder-pm 3 minutes ago
      This matrix is not a condition, it’s a key. JSON.stringify with it’s data goes to the scrypt as a password and that creates an AES-256-GCM key. There is no if, every other input won’t decrypt. That’s why no one will get payload from the package without knowing the exact input.
    • zarzavat 46 minutes ago
      Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.
      • krackers 2 minutes ago
        Now I'm curious what the target was. Are there any notable classes of programs/problems where you'd do an LU decomposition of this specific matrix?
    • tranceylc 20 minutes ago
      I would assume it’s actually so they can allow it to spread before it gets activated. Then do something that affects the entire chain of package dependencies
  • nextzck 38 minutes ago
    Fascinating how intricate the target selection is on this
  • hiddenvulkcan 33 minutes ago
    [dead]
  • TZubiri 32 minutes ago
    My strategy of not using dependencies at all seems to be getting stronger everyday.

    Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.

    Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.

    • iLoveOncall 8 minutes ago
      Let us know in 2838 when you finish your first program, would love to check it out!