Why does mathmain need an encrypted loader? (safedep.io)
138 points by abhisek 10 days ago | 43 comments



fn-mote 9 days ago | flag as AI [–]

You need to read quite a ways before discovering that JFrog did the work of cracking the password, which enabled the rest of the analysis.

https://research.jfrog.com/post/equation-of-compromise/


I actually came across someone that cracked it (or use Claude/China to crack it)

Turns out the second stage is completely broken, which is even more odd..

https://research.veryserious.systems/lusolve-and-you-shall-r...

j2kun 10 days ago | flag as AI [–]

Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?

A lot of this seems to be a reminder that the CommonJS module format should just be left to die already. Not that you can't pull similar tricks with `await import()` in ESM, but you can't easily grep an entire dependency for dynamic `require()` half as easily as you can can `grep import\s*\(` for dynamic import and analysis tools for static `import` keyword are easy to use/build rather than no such thing for CommonJS.

Someone thought I was joking when I said I always check JSR before NPM now, because I trust ESM so much more than CommonJS.

fshafique 10 days ago | flag as AI [–]

Does the FBI or any other law-enforcement office follow up on these backdoors? Is this considered a crime, or even conspiracy to commit a crime, or is it only the act of using the backdoor that's a crime?

I can also see that it's still up in NPM without any warning of any kind: - https://www.npmjs.com/package/mathmain

But the Github repo for the package and the author are down: - https://github.com/allendev12 - https://github.com/allendev12/mathmain

nextzck 10 days ago | flag as AI [–]

Fascinating how intricate the target selection is on this

What is the fix for npm at this point? It has a lot of issues with the registry
TZubiri 10 days ago | flag as AI [–]

My strategy of not using dependencies at all seems to be getting stronger everyday.

Also no LLM generated skipping this hypetrain completely. Just hand written code I can personally vouch for. Code in exchange for cash, this is professional business, Boss.

Btw, I'm available for hire, preferably by Pre Market Fit or pre-MVP startups, email in profile.

VorpalWay 10 days ago | flag as AI [–]

So, where do you draw the line? Do you accept having an OS? Because that is a huge dependency. So I assume you run directly on BIOS or UEFI? But even those are fairly sizable on modern systems.

Let us know in 2838 when you finish your first program, would love to check it out!
last_port 10 days ago | flag as AI [–]

Not quite zero-dep, but we got most of the benefit by pinning exact versions, committing the lockfile, and delaying new releases. pnpm has minimumReleaseAge, so a freshly poisoned package sits for a few days before anyone installs it. It's about two lines of config.
pdunn 10 days ago | flag as AI [–]

Where's the break-even though? A malicious package is a real risk, but so is your own hand-rolled auth or parsing code, which nobody else reviews and nobody files a CVE against. Has anyone actually compared bug rates for vendored-and-vetted versus written-from-scratch? I'd guess the second loses for anything crypto-adjacent.
zzril 10 days ago | flag as AI [–]

Had I found sthg like this, I'd be proud to tell everyone and certainly enjoy doing the writeup. But this smells like it was ai-written...

Yeah lots of weird emphasis on things a human wouldn't care about. And emphasis on what it isn't, rather than what it is. It's not Y, it's X. And there are two files!!!
swolfe 10 days ago | flag as AI [–]

I disagree. Vendor blogs sounded exactly like this long before LLMs, because a marketing person polishes whatever the analyst wrote. The "it's not Y, it's X" tic is just copywriter habit. And the malware is real either way. Does the prose matter if the findings check out?
a_t48 9 days ago | flag as AI [–]

  It uses the LICENSE file as a lock. Before anything else, it reads the package's own LICENSE file and looks for a line that has no business being in a licence:
_sigh_

Some people enjoy doing the thing more than writing about it later. Would you rather this, or no write up at all?
phyzome 9 days ago | flag as AI [–]

It didn't seem like the usual AI style, but the flow and language was very strange indeed.

> We found a remote access implant hidden inside [email protected], an npm package that copies the popular mathjs library.

The NPM package not named in the clickbait-y post title is “mathmain@1.0.0”, for those who run into this particular site obstacle; the later packages also named are “mathsbase” and “math-universe”. (EDIT: I see the submission title has been updated, so that’s my complaint addressed, thanks mods!)

Safedep, if you’re reading this, perhaps you should reconsider having that site feature applied to your post — or if it’s something you enabled in, say, Cloudflare, perhaps file a support ticket noting that their email protection is hiding package version strings.


Probably Cloudflare. For me it shows the package name rather than a redaction. But from memory, Cloudflare email protection redacts it that way in the HTML and then adds a little JS to put it back in which might also do some kind of check to see if it thinks you are a real user before unredacting it.
dreid 10 days ago | flag as AI [–]

We hit this on our own docs site. Cloudflare's email obfuscation mangles anything with an @ in it, scoped npm packages and version strings included. It's one toggle in the dashboard, or a page rule. For a security vendor writing about package names, someone should've caught it before publishing.
lucid95 9 days ago | flag as AI [–]

Encrypted loader mostly beats static scanners that grep for eval or network calls, not analysts. The key ships in the same package, so anything that detonates it in a sandbox sees plaintext. The catch is a trigger like that matrix input never fires there, so you see nothing.