Containing Malicious Package Updates in npm with a Lightweight Permission System
Gabriel Ferreira, Limin Jia, Joshua Sunshine, Christian Kästner
Abstract
The large amount of third-party packages available in fast-moving software ecosystems, such as Node.js/npm, enables attackers to compromise applications by pushing malicious updates to their package dependencies. Studying the npm repository, we observed that many packages in the npm repository that are used in Node.js applications perform only simple computations and do not need access to filesystem or network APIs. This offers the opportunity to enforce least-privilege design per package, protecting applications and package dependencies from malicious updates. We propose a lightweight permission system that protects Node.js applications by enforcing package permissions at runtime. We discuss the design space of solutions and show that our system makes a large number of packages much harder to be exploited, almost for free.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers20
- Practical Automated Detection of Malicious npm PackagesAdriana Sejfia, Max SchäferICSE 2022 · 65 citations
- LastPyMile: identifying the discrepancy between sources and packagesDuc-Ly Vu, Fabio Massacci, Ivan Pashchenko, Henrik Plate et al.FSE 2021 · 53 citations
- DONAPI: Malicious NPM Packages Detector using Behavior Sequence Knowledge MappingCheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun et al.USENIX Security 2024 · 38 citations
- SandTrap: Securing JavaScript-driven Trigger-Action PlatformsMohammad M. Ahmadpanah, Daniel Hedin, Musard Balliu, Lars Eric Olsson et al.USENIX Security 2021 · 31 citations
- Leveraging Practitioners' Feedback to Improve a Security LinterSofia Reis, Rui Abreu, Marcelo d'Amorim, Daniel FortunatoASE 2022 · 16 citations
Builds on5
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 281 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- CHAINIAC: Proactive Software-Update Transparency via Collectively Signed Skipchains and Verified BuildsKirill Nikitin, Eleftherios Kokoris-Kogias, Philipp Jovanovic, Nicolas Gailly et al.USENIX Security 2017 · 144 citations
- SYNODE: Understanding and Automatically Preventing Injection Attacks on NODE.JSCristian-Alexandru Staicu, Michael Pradel, Benjamin LivshitsNDSS 2018 · 91 citations
- BreakApp: Automated, Flexible Application CompartmentalizationNikos Vasilakis, Ben Karel, Nick Roessler, Nathan Dautenhahn et al.NDSS 2018 · 66 citations
Related papers
- Preventing Dynamic Library Compromise on Node.js via RWX-Based Privilege ReductionNikos Vasilakis, Cristian-Alexandru Staicu, Grigoris Ntousakis, Konstantinos Kallas et al.CCS 2021 · 27 citations
- HODOR: Shrinking Attack Surface on Node.js via System Call LimitationWenya Wang, Xingwei Lin, Jingyi Wang, Wang Gao et al.CCS 2023 · 3 citations
- Not All Dependencies are Equal: An Empirical Study on Production Dependencies in NPMJasmine Latendresse, Suhaib Mujahid, Diego Elias Costa, Emad ShihabASE 2022 · 17 citations
- Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its EcosystemAbdullah AlHamdan, Cristian-Alexandru StaicuNDSS 2025
- NodeShield: Runtime Enforcement of Security-Enhanced SBOMs for Node.jsEric Cornelissen, Musard BalliuCCS 2025
