This project is not maintained anymore. You can still view and search the archives.

wdrl.
  • Archive
  • Evergreen
  • About
  • Contribute

Malicious crossenv package on npm

Hi, I’m Anselm Hannemann, a freelance Frontend Developer and Engineering Manager. You can hire me. I wrote WDRL for 10 years and have a a Market Garden as a side-business.

Profile photo of the author, Anselm Hannemann

This link appeared in WDRL 192 on 04.08.2017.

Malicious crossenv package on npm

This week a new big incident happened with several npm packages. An unknown author re-published a lot of common packages with very similar names and injected malware into the code, stealing all environment variables of the machine where the package gets installed. They’re pulled from the registry now but if you ever installed them somewhere by accident, it’s not easy to spot it and you should consider your data to be stolen.

This link appeared in the 2017 Yearbook.

Profile photo of the author, Anselm Hannemann

Other projects

  • Hire me as Developer or Scrum Master
  • My food produce CSA

Sitemap

  • Privacy Policy
  • RSS
  • Donate
  • About
  • Testimonials

Legal

© 2026 and made by
Anselm Hannemann
Hofmark 14
82393 Iffeldorf
Germany
mail@wdrl.info