Skip to content
Threat Feed
medium advisory

Detection of Malicious Curl Downloads during npm Package Installation

Malicious npm packages and supply-chain compromises often utilize installation scripts to spawn curl processes that download secondary payloads from remote servers.

Malicious npm packages and supply-chain compromises frequently abuse Node.js lifecycle scripts (such as install or postinstall) to fetch second-stage payloads from remote infrastructure. Attackers leverage the trust inherent in package management workflows to execute code during the npm install or npx process. This threat specifically involves the spawning of curl from within a Node.js process tree initiated by npm or npx CLI tools. By using short command-line arguments and standard output redirection or shell execution, these malicious scripts attempt to minimize their footprint while retrieving external malicious resources. Defenders should monitor for Node.js-originated processes that invoke curl to download remote files, as this is a high-fidelity indicator of potential dependency tampering.

Impact

Successful exploitation allows attackers to gain arbitrary code execution within the build environment or developer workstation. This can lead to the exfiltration of sensitive environment variables, developer credentials, and project-specific API tokens, or result in the injection of persistent backdoors into build artifacts, potentially affecting downstream users of the compromised software.

Recommendation

  • Implement monitoring for child processes spawned by Node.js package managers to identify unauthorized outbound network connectivity.
  • Review package.json lifecycle scripts for suspicious activity or obfuscated commands before executing dependency installations in CI/CD pipelines.
  • Isolate build environments and restrict internet access for package manager processes, allowing only access to trusted, hardened private registries.
  • Investigate any curl activity initiated by npm or npx process trees identified in endpoint telemetry.

Immediate actions

Review endpoint logs for Node.js-based process trees initiating curl.

SOC 24h

Threat Hunt

Search for curl processes where the parent process command line contains 'npx-cli.js', 'npm-cli.js', or '.npm/_npx/'.

T1195.001 high high confidence hunt now

Data: Process creation events