The coa npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 4 Nov 2021 · npm

Packagecoa 2.0.2 -> 2.0.3 (also 2.0.4, 2.1.1, 2.1.3, 3.0.1, 3.1.3)
Filepackage.json gained "preinstall": "start /B node compil...

The npm package coa was hijacked on 4 November 2021. Versions 2.0.3, 2.0.4, 2.1.1, 2.1.3, 3.0.1, and 3.1.3 contain malicious code. The last safe version is 2.0.2.

The same attacker also hijacked the rc package. This page lists the affected versions, the files to look for, and the steps to take.

What happened

An attacker published malicious versions of coa to npm after the maintainers lost control of the package. The GitHub issue thread shows the first bad version went live on 4 November 2021 at 14:12 CET. npm removed it at 15:24 CET, about 72 minutes later.

The bad package added a preinstall script to package.json:

"preinstall": "start /B node compile.js & node compile.js"

This script starts compile.js in the background when a user installs the package. Rapid7 reports that the malware steals credentials and that npm found the same malware in the rc hijack. Rapid7 says the rc variant targets Windows.

The attack broke some builds. Dependent packages such as @svgr/cli failed with the error Cannot find module '/...coa/compile.js'. Antivirus software also flagged the file. The maintainers later regained access to the package.

Affected versions

The GitHub advisory GHSA-73qr-pfmq-6rp8 lists six affected coa versions. It rates the issue critical and has no CVE.

The advisory lists no patched version for coa. It tells users to downgrade to 2.0.2. The weakness class is CWE-506, embedded malicious code.

Indicators of compromise

Rapid7 lists three file names to search for on a suspect system.

The sources do not list network indicators. Do not treat a clean search as proof that a machine is safe if it installed an affected version.

How to check

Run npm ls in each project to see which coa and rc versions your tree resolves. Transitive dependencies show here too.

npm ls coa rc

Search lockfiles for the bad versions.

grep -rE '"(coa|rc)"' package-lock.json yarn.lock pnpm-lock.yaml 2>/dev/null

Then search the machine for the files from the indicator list. On Windows, use a file search for compile.js, compile.bat, and sdd.dll. On macOS and Linux, run this in the project folder.

find node_modules -path '*coa*' -name compile.js

What to do now

  1. Pin coa to 2.0.2 and rc to 1.2.8 with resolutions or overrides.
  2. Delete node_modules and reinstall from a clean lockfile.
  3. If a machine installed an affected version, treat it as fully compromised.
  4. Rotate all credentials, tokens, and keys that the machine stored. Do this from a different, clean computer.
  5. Look for compile.js, compile.bat, and sdd.dll on the machine.
  6. Check the machine for other suspicious activity.

Vigilance compares the version you trust with the new one. Here, coa 2.0.2 had no install script. The poisoned versions added one and added new executable files. That change shows in the diff between the two versions.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old coa-2.0.2 --new coa-2.0.3
files scanned: 13

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which coa versions are malicious?

Versions 2.0.3, 2.0.4, 2.1.1, 2.1.3, 3.0.1, and 3.1.3 are affected. The last safe version is 2.0.2.

What do I do if I installed a bad coa version?

Treat the machine as compromised. Downgrade to 2.0.2, search for compile.js, compile.bat, and sdd.dll, and rotate all stored credentials from a different computer.

Sources

  1. github.com/advisories/GHSA-73qr-pfmq-6rp8
  2. github.com/veged/coa/issues/99
  3. rapid7.com/blog/post/2021/11/05/new-npm-library-hijacks-coa-and-rc/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free