Skip to content
Threat Feed
high advisory

Malicious PowerShell Execution via npm Package Lifecycle Scripts

Malicious or compromised npm packages leverage installation lifecycle scripts to launch obfuscated PowerShell or download cradles, enabling initial access and secondary payload deployment.

This threat involves the exploitation of the Node.js package ecosystem, specifically targeting npm lifecycle scripts such as 'postinstall'. Attackers distribute malicious npm packages or compromise legitimate dependencies to execute arbitrary code during the standard package installation process. The attack chain leverages the 'npx' command or standard 'npm install' routines to invoke Node.js, which subsequently spawns PowerShell processes. These PowerShell instances are used to execute encoded commands or initiate network connections via download cradles (e.g., 'Invoke-WebRequest', 'DownloadString', 'BITS'). This technique is highly effective for supply-chain compromise as it allows an attacker to execute code in developer or build environments with the privileges of the user running the installation. Defenders should monitor for suspicious process ancestry where Node.js spawns PowerShell, particularly when the command line includes obfuscation or common download cradle functions.

Attack Chain

  1. Attacker publishes a malicious package to the public npm registry or compromises a legitimate, widely-used dependency.
  2. A developer or automated build system executes 'npm install' or 'npx <package>' within an environment.
  3. The npm client initializes the Node.js runtime, invoking 'npm-cli.js' or 'npx-cli.js'.
  4. The package's 'postinstall' script triggers, executing a system command via Node.js.
  5. The spawned process initiates a PowerShell instance to bypass execution policy or obfuscate activity.
  6. The PowerShell script uses download cradles (e.g., 'IEX', 'Net.WebClient') to fetch a secondary stage payload from an attacker-controlled remote server.
  7. The secondary payload is executed in memory or written to disk to establish persistence or remote command-and-control access.

Impact

Successful exploitation results in unauthorized code execution within the victim's development or build environment. This can lead to credential theft, intellectual property exfiltration, the injection of malicious code into downstream software products, and further lateral movement within the organization's CI/CD pipeline.

Recommendation

Prioritize visibility into developer and build environment process lineage. Enable process-creation logging and specifically monitor for instances where 'node.exe' serves as the parent process to 'powershell.exe'.

  • Deploy detection rules that inspect process ancestry to identify PowerShell spawned from Node.js (specifically 'npm-cli.js' or 'npx-cli.js').
  • Audit 'package.json' files in local repositories for suspicious lifecycle scripts (e.g., 'preinstall', 'postinstall').
  • Review network logs for outbound connections from build servers to unknown or high-risk domains, especially when initiated by PowerShell.
  • Implement and enforce dependency locking (e.g., 'package-lock.json') to mitigate risks from malicious package updates.

Immediate actions

Deploy the Sigma-compatible rule to monitor for PowerShell processes spawned by node.js.

Detection Engineering 48h

Threat Hunt

Search for recent process logs where parent process is node.exe and child is powershell.exe.

T1059.001 high high confidence hunt now

Data: Process creation events (Event ID 1)

Mitigations

Enforce the use of lockfiles and dependency scanning tools in CI/CD pipelines.

medium_term IT Operations

T1195.001

Detection coverage 1

Detect Suspicious PowerShell from npm Package Install

high

Detects PowerShell launched with an encoded command or a download cradle whose process ancestry includes a Node.js npm package execution.

sigma tactics: execution techniques: T1059.001, T1195.001 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →