Skip to content

Dependency Confusion Attack via Unregistered Internal npm Package (videojs-v8) #9201

Description

@anguprasad07

Description

A dependency confusion vulnerability was identified in the Motive web application (app.gomotive.com). A JavaScript bundle served at the following URL references an internal/private npm package — videojs-v8 — that has no corresponding entry on the public npm registry:

https://app.gomotive.com/en-US/4836.aa94c96528a199d39fc7.js

The source map embedded in the response reveals the internal package path:

webpack://./node_modules/videojs-v8/dist/video-js.css

Because videojs-v8 is not registered on https://registry.npmjs.org/videojs-v8, an attacker can publish a malicious package under that name on the public npm registry with a higher version number. If a developer or CI/CD pipeline runs npm install without a private registry lock, npm's default resolution will prefer the public registry version, causing the malicious package to be installed instead.

Impact

An attacker can claim the unclaimed videojs-v8 package on the public npm registry and inject malicious code that executes automatically during npm install in developer or CI/CD environments. This can lead to full RCE on build infrastructure, secret/credential exfiltration, and poisoned production artifacts being deployed to Motive's platform.

Recommendation

Immediately register videojs-v8 on npmjs.org as a placeholder to prevent hostile takeover, and migrate the package to a scoped name (e.g., @motive/videojs-v8) long-term. Enforce private registry resolution via .npmrc so internal packages are never resolved from the public registry. Additionally, disable webpack source maps in production builds to prevent leaking internal package names and paths.

Reduced test case

https://abc.com/en-US/4836.aa94c96528a199d39fc7.js

Steps to reproduce

  1. Fetch the public bundle to confirm the internal package reference
  2. In the response body, locate the embedded source map referencing:
    "webpack://./node_modules/videojs-v8/dist/video-js.css"
  3. Confirm the package is unclaimed on npm:
    GET https://registry.npmjs.org/videojs-v8

Errors

No response

What version of Video.js are you using?

v8

Video.js plugins used.

No response

What browser(s) including version(s) does this occur with?

Chrome

What OS(es) and version(s) does this occur with?

Mac

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs: triageThis issue needs to be reviewed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions