NPM’s Scale Creates a Scanning Blind Spot
NPM holds almost 4 million packages. 140,000 updates and 3,800 new packages arrive every day. Two years ago that number was under 1, less than 1,000. Metadata can be faked. NPM accepts whatever you tell it. JavaScript’s transitive dependencies average 680 per package, 10x the next language. Debug, the fourth most downloaded package, has 380 million downloads and is controlled by a small group. Account takeover attacks are common.
Canary Packages Reveal the Scanners
McCarty embedded canary tokens from Think Canary into NPM packages. The tokens fire when a package is installed, imported, or opened. He used eight types: JavaScript payloads, binaries, Word and Excel files, AWS credentials, DNS tokens, local credential files, PDFs, and web images in readmes. The JavaScript payloads report hostname and public IP. The canaries only trigger for organizations, not random developers. A live map shows where triggers originate.
Cloud Providers: Fast Scanning with Different Agendas
Google scans from Council Bluffs, Iowa. Microsoft scans from Virginia hosts Microsoft’s scans. AWS scans from multiple US locations and occasionally India. Alibaba, Tencent Volcano Engine (ByteDance), and other Chinese providers scan from many IPs inside China. AWS scans every new package in under 5 minutes. A team at AWS, led by Chai Tran, submits malicious packages to OSV. Microsoft’s internal scanner finds very few packages. NPM leans on the researcher community.
Security Vendors: Narrow Focus and Wasted Compute
ReversingLabsingLabs scans NPM for AWS credentials only. They scan the same unchanged package three to four times daily. McCarty asked why; they said they are testing product capabilities. Kaspersky scans most packages within 10 to 12 minutes from three Russian locations. They only look for Word and Excel files. They scan once per release. Kaspersky’s IPs also appear in Shodan and VirusTotal for mass recon scanning of WordPress and Joomla.
China and Russia: Mass Scanning from Old Infrastructure
Chinese cloud providers scan every NPM package for everything, all the time, from five to eight different locations. Many IPs have been in use for years. One user agent string reveals a CentOS 7 from 2018. Russian scans originate from VimpelCom, an ISP now owned by Russian interests. They are slower, hitting new packages between 2 and 10 hours after release. Some scans appear to be standard ISP activity; others look automated.
Coverage Gaps and the Need for Dynamic Analysis
Most security companies use static analysis and do not run packages in a sandbox. AWS, Azure, and Chinese providers do run them dynamically. Static analysis misses second-stage loaders and the rest of the kill chain. ReversingLabs wastes compute scanning unchanged packages. Kaspersky only covers Word and Excel. Adversaries can evade detection by targeting these gaps. McCarty is using the data to map patterns and find where payloads can slip through.
Q&A
How often are people using NPM to distribute Word and Excel files? Kaspersky likely targets accidental exposure, like the visa company that leaked passport data. ▶ 31:27
What are your thoughts on SCA companies looking for package malware? SCA is built for accidental vulnerabilities, not intentionally malicious packages. Most SCA tools do not detect malware well. ▶ 32:05
Are there alternatives to NPM or tips to use it safely? PNPM improves local security but still uses the NPM registry. The registry itself is the biggest problem. NPM now requires MFA for publishes, which helps. ▶ 33:12
How do you distinguish AWS the cloud provider from AWS customers scanning? Metadata like user agent strings and IP patterns separate them. Anomalies stand out at scale. More detail will come in the third talk. ▶ 35:49
Notable Quotes
npm’s doing a pretty crappy job of scanning npm itself. Paul McCarty · ▶ 11:16
ReversingLabs ReversingLabs has been scanning NPM for a long time. But they care about one thing and only one thing. AWS credentials. Paul McCarty · ▶ 15:30
Kaspersky is only really interested in Word and Excel files. Paul McCarty · ▶ 18:07
they are scanning every single NPM package for everything all the time from like five to eight different places. Paul McCarty · ▶ 20:02
the watchers can be watched to detect patterns Paul McCarty · ▶ 28:47
Key Takeaways
- NPM’s own scanning is weak; Microsoft relies on researchers to find malicious packages.
- Canary packages reveal that scanners have narrow focus, leaving coverage gaps.
- Adversaries can exploit gaps by using dynamic payloads that static analysis misses.
About the Speaker(s)
Paul McCarty is the founder and maintainer of OpenSourceMalware.com, the world’s largest open database and collaboration platform for software supply chain threat intel. He loves software supply chain research and delivering supply chain offensive security training and engagements. He has spent the last two years deep-diving into npm and has made several contributions to the field.