Miggo Logo

CVE-2017-16057: nodemssql is malware

7.5

CVSS Score
3.0

Basic Information

EPSS Score
0.50324%
Published
11/9/2018
Updated
9/14/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
nodemssqlnpm<= 1.0.2

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The advisory identifies the entire 'nodemssql' package as malicious but does not provide specific function-level details or code samples. The vulnerability manifests through embedded malicious code (CWE-506) that exfiltrates environment variables, but without access to the unpublished package's source code, commit diffs, or explicit documentation of malicious functions, we cannot confidently identify specific vulnerable functions. The lack of GitHub patch information and commit diffs further limits our ability to pinpoint exact malicious code paths.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T** `no**mssql` p**k*** is * pi*** o* m*lw*r* t**t st**ls *nvironm*nt v*ri**l*s *n* s*n*s t**m to *tt**k*r *ontroll** lo**tions. *ll v*rsions **v* ***n unpu*lis*** *rom t** npm r**istry. ## R**omm*n**tion *s t*is p**k*** is m*lw*r*, i* you *in*

Reasoning

T** **visory i**nti*i*s t** *ntir* 'no**mssql' p**k*** *s m*li*ious *ut *o*s not provi** sp**i*i* *un*tion-l*v*l **t*ils or *o** s*mpl*s. T** vuln*r**ility m*ni**sts t*rou** *m****** m*li*ious *o** (*W*-***) t**t *x*iltr*t*s *nvironm*nt v*ri**l*s, *u