Miggo Logo

CVE-2017-16063: node-opensl is malware

7.5

CVSS Score
3.0

Basic Information

EPSS Score
0.50347%
Published
10/3/2018
Updated
9/12/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
node-openslnpm> 0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The advisory describes node-opensl as embedded malware but provides no source code, commit diffs, or specific function-level details. While we can infer malicious functionality would likely involve environment variable access (process.env) and network exfiltration, the lack of concrete code examples or function names in available resources prevents high-confidence identification of specific vulnerable functions. The package has been unpublished from npm, further limiting analysis opportunities. CWE-506 (Embedded Malicious Code) indicates the entire package should be considered malicious rather than containing specific vulnerable functions.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

T** `no**-op*nsl` p**k*** is * pi*** o* m*lw*r* t**t st**ls *nvironm*nt v*ri**l*s *n* s*n*s t**m to *tt**k*r *ontroll** lo**tions. *ll v*rsions **v* ***n unpu*lis*** *rom t** npm r**istry. ## R**omm*n**tion *s t*is p**k*** is m*lw*r*, i* you *i

Reasoning

T** **visory **s*ri**s `no**-op*nsl` *s *m****** m*lw*r* *ut provi**s no sour** *o**, *ommit *i**s, or sp**i*i* `*un*tion-l*v*l` **t*ils. W*il* w* **n in**r m*li*ious *un*tion*lity woul* lik*ly involv* *nvironm*nt v*ri**l* ****ss (`pro**ss.*nv`) *n*