Reliance on psl < 1.1.29 could pull in malicious code
envgap__salesforce__tough-cookie-134
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
296a98f911f37b84ed625f5545594d49b73ef61d- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
salesforce/tough-cookie #134 · read the original issue
The psl module is used as a dependency with semver `^1.1.28`. Prior to psl version 1.1.30, psl had a development dependency on event-stream with semver `^3.3.4`. event-stream 3.3.5 included a dependency on flatmap-stream, which contained [malicious code](https://github.com/dominictarr/event-stream/issues/116) designed to steal bitcoins. As such, if when building tough-cookie a version of psl is used prior to 1.1.30 (which is possible due to the semver specification), and psl pulls in event-stream 3.3.5 (also possible), the malicious code would be included. While npm has removed the version containing malicious code, requiring the latest version of psl will also require event-stream 3.3.4, which will protect people who might have cached copies of event-stream 3.3.5. Sorry if this is confusing -- there are lots of version numbers here!
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]