Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Malware detected in dependabot core image by AWS Inspector #11766

Open
1 task done
edmundackah opened this issue Mar 8, 2025 · 0 comments
Open
1 task done

Malware detected in dependabot core image by AWS Inspector #11766

edmundackah opened this issue Mar 8, 2025 · 0 comments
Labels
L: javascript T: bug 🐞 Something isn't working

Comments

@edmundackah
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Package ecosystem

npm

Package manager version

all

Language version

Node.js

Manifest location and content before the Dependabot update

🐞 Bug report

AWS Inspector is flagging malware in all of the dependabot-core images. This means we are unable to use the npm variant. The node version I want to support with this image is 14.21.x 20.x and 22.x. Can we remove these malicious packages from the images? Anyone else trying to run the images in a cloud environment with container image scanning will encounter the same issues. I am happy to provide any additional material

Here are the findings from inspector.

Finding 1: MAL-2022-2944 (extraneous-detected)

Field Details
Finding ID arn:aws:inspector2:eu-west-1:[REDACTED]:finding/9151963e624829556c00a0cc75bff549
Severity Critical
Vulnerability ID MAL-2022-2944
Vulnerability Source OSSF
CVSS 3.1 Score 9.8 (Critical)
Package Name extraneous-detected
Installed Version 0:0.0.0
Fixed Version Not Available
Package Manager NODE
File Path /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test
Type Package Vulnerability
Severity Critical
Exploit Available No
Fix Available No
Image Operating System UBUNTU 22.04
Image Tag 551f7ee3-20250307-1039
Image ID [REDACTED]
Pushed At March 7, 2025, 10:39 AM (UTC+00:00)

Finding 2: MAL-2022-2945 (extraneous-dev-dep)

Field Details
Severity Critical
Vulnerability ID MAL-2022-2945
Vulnerability Source OSSF
CVSS 3.1 Score 9.8 (Critical)
Package Name extraneous-dev-dep
Installed Version 0:0.0.0
Fixed Version Not Available
Package Manager NODE
File Paths /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-dev-dep/package.json
Exploit Available No
Fix Available No
Type Package Vulnerability
Image Operating System UBUNTU 22.04
Image ID [REDACTED]
Image Tag 551f7ee3-20250307-1039
Repository dependabot-npm
AWS Account ID [REDACTED]
Registry [REDACTED]
Pushed at March 7, 2025, 10:39 AM (UTC+00:00)

Finding 3: MAL-2022-6485 (test-old-npm-sub-dependency)

Field Details
Severity Critical
Vulnerability ID MAL-2022-6485
Vulnerability Source OSSF
CVSS 3.1 Score 9.8 (Critical)
Package Name test-old-npm-sub-dependency
Installed Version 0:github:dependabot-fixtures/test-old-npm-sub-dependency#3022e23aa7dac4d
Fixed Version Not Available
Package Manager NODE
File Paths /home/dependabot/npm8/nested_sub_dependency_update_npm_out_of_range/packages/package4/package-lock.json (+2 more)
Exploit Available No
Fix Available No
Inspector Score 9.8
Repository dependabot-npm
AWS Account ID [REDACTED]
Registry [REDACTED]
Image ID [REDACTED]
Image Operating System UBUNTU 22.04
Image Tag 551f7ee3-20250307-1039
Pushed at March 7, 2025, 10:39 AM (UTC+00:00)

Finding 4: MAL-2023-462 (fsevents)

Field Details
Severity Critical
Vulnerability ID MAL-2023-462
Vulnerability Source OSSF
CVSS 3.1 Score 9.8 (Critical)
Package Name fsevents
Installed Version 0:1.2.2
Fixed Version 1.2.11
Package Manager NODE
File Paths /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm6/os/package-lock.json, /home/dependabot/npm_and_yarn/node_modules/npm/package-lock.json
Exploit Available No
Fix Available Yes (Upgrade to 1.2.11)
Inspector Score 9.8
Repository dependabot-npm
AWS Account ID [REDACTED]
Registry [REDACTED]
Resource Type AWS ECR Container Image
Image ID [REDACTED]
Image Operating System UBUNTU 22.04
Image Tag 551f7ee3-20250307-1039
Pushed at March 7, 2025, 10:39 AM (UTC+00:00)

In addition, these paths have also been flagged.

# File Path
1 /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-detected/package.json
2 /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-detected/
3 /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test/
4 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm6/os_mismatch/package-lock.json
4 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm8/os_mismatch/package-lock.json
5 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm6/os_mismatch/package-lock.json
6 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm8/os_mismatch/package-lock.json
7 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm8/subdependency_update_tab_indentation/
8 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm6/subdependency_update_tab_indentation/package-lock.json
8 /home/dependabot/npm_and_yarn/spec/fixtures/updated_projects/npm6/subdependency_update_tab_indentation/package-lock.json
9 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm6_and_yarn/nested_sub_dependency_update_npm_out_of_range/packages/package4/package-lock.json
10 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm8/subdependency_update_tab_indentation/
11 /home/dependabot/npm_and_yarn/spec/fixtures/updated_projects/npm8/subdependency_update_tab_indentation/
11 /home/dependabot/npm_and_yarn/spec/fixtures/projects/npm8/subdependency_update_tab_indentation/
12 /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test/fixtures/extraneous-dev-dep/package.json
13 /opt/npm_and_yarn/node_modules/npm/node_modules/
14 /opt/npm_and_yarn/node_modules/npm/node_modules/read-installed/test/fixtures/
14 /opt/npm_and_yarn/node_modules/npm/package-lock.json
15 /opt/npm_and_yarn/node_modules/

Package ecosystem

npm

dependabot.yml content

No response

Updated dependency

No response

What you expected to see, versus what you actually saw

Shouldn not see any malware detected in my inspector scan report

Native package manager behavior

No response

Images of the diff or a link to the PR, issue, or logs

No response

Smallest manifest that reproduces the issue

No response

@edmundackah edmundackah added the T: bug 🐞 Something isn't working label Mar 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
L: javascript T: bug 🐞 Something isn't working
Projects
Status: No status
Development

No branches or pull requests

1 participant