logo

Database

Use of software with malware In @bananacool467/ui-tools

Description

The package advertises itself as a UI-components library (README compares it to MUI), but its main export surface includes useTerminal, a server-side middleware that stands up a WebSocketServer (default path /terminal-stream) and, on every incoming WS message, spawns an interactive bash/powershell PTY via pty.spawn with the server process's own environment ({...process.env, TERM: 'xterm-256color'}) and cwd set to the user's home directory. Bytes received from the WebSocket are written directly into the PTY (session.ptyProcess.write(parsed.data), with a fallback that writes raw message bytes), and PTY output is streamed back to the socket. No authentication, origin check, or handshake token gates the connection. dist/terminal.js ships the matching browser client (exported as Terminal) that connects to that same WebSocket and pipes keystrokes as {type:'input', data:...}, so the package ships both ends of a remote-shell channel. A consumer who mounts the exported hook — expecting a UI helper — exposes a full unauthenticated interactive shell on their server, executing as the server process. The mismatch between the marketed purpose (UI kit) and the shipped capability (network-driven RCE) is the shape of a backdoor delivered under a benign cover story.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version