All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

DuckDB npm packages 1.3.3 and 1.29.2 compromised with cryptocurrency-targeting malware

By

tosh

8mo ago· 3 min readenCode

Summary

The DuckDB npm packages (duckdb, @duckdb/node-api, @duckdb/node-bindings, and duckdb-async) were compromised with malware in versions 1.3.3 and 1.29.2. An attacker published malicious code designed to interfere with cryptocurrency transactions. The legitimate current release is 1.3.2, and users are warned not to update to the affected versions. DuckDB has no plans to release a legitimate 1.3.3 version.

Key quotes

· 3 pulled
The DuckDB distribution for Node.js on npm was compromised with malware (along with several other packages).
An attacker published new versions of four of duckdb's packages that included malicious code to interfere with cryptocoin transactions.
We do not plan to ever release a 'legit' DuckDB 1.3.3. Users should double-check that they are not accidentally updating to those affected versions.
Snippet from the RSS feed
The DuckDB distribution for [Node.js](http://node.js/) on [npm](https://www.npmjs.com/) was compromised with malware (along with [several other packages](https://www.aikido.dev/blog/npm-debug-and-c...

You might also wanna read