<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

'PackageGate' Vulnerabilities Expose JavaScript Package Managers to Supply Chain Attacks

Security firm Koi uncovers 'PackageGate' vulnerabilities in JavaScript package managers, posing risks of malicious code execution.
Content Team

Security firm Koi discovered six vulnerabilities dubbed 'PackageGate' affecting major JavaScript package managers including NPM, PNPM, VLT, and Bun. These flaws can bypass existing supply chain protections, allowing attackers to execute malicious code through compromised dependencies.

The vulnerabilities work differently across managers: NPM can be exploited through malicious .npmrc files in Git dependencies, while PNPM's script protections don't cover Git processing. VLT has path traversal issues in tarball extraction, and Bun's allow lists can be spoofed.

PNPM, VLT, and Bun quickly patched their issues, but NPM dismissed the report as 'informative,' claiming the behavior works as intended. GitHub maintains that users accept repository risks when installing Git dependencies.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo