The PureScript npm Installer Sabotage

Updated 5 Oct 2026 · Incident date 5 Jul 2019 · npm

Packageload-from-cwd-or-npm 3.0.1 -> 3.0.2 and rate-map 1.0.2 -> 1.0.3
Fileindex.js in both packages: load-from-cwd-or-npm/index.j...

Two npm packages, load-from-cwd-or-npm 3.0.2 and rate-map 1.0.3, sabotaged the PureScript npm installer in July 2019. They made the installer hang instead of finishing. The code did not steal data.

Both packages belonged to the same maintainer, who was a former author of the installer.

What happened

The PureScript installer is a package that downloads a prebuilt compiler. Its maintainers took over from the original author, Shinnosuke Watanabe (@shinnn), after a disagreement, according to The Register. The PureScript 0.13.2 release on 5 July 2019 was the first from the new team.

The PureScript maintainer's write-up gives this timeline in UTC:

The first package returned a PassThrough stream instead of the expected package, so the installer hung at the step that checks for a prebuilt binary. The second package removed callback behavior and deleted itself to hide evidence. The code ran only when the PureScript installer used it, and not when the original author's own packages did.

Watanabe said an attacker gained access to his npm account. The Register notes that this is not settled.

Affected versions

Both malicious versions were later removed from the registry. The write-up recommends upgrading to PureScript 0.13.2 or later, and says the maintainers removed or copied into their own code all dependencies by @shinnn. This is only partly detectable by comparing files. The 3.0.2 change gave the package no new capability, because it only returned a wrong value.

Indicators of compromise

How to check

List the two packages in your dependency tree.

npm ls load-from-cwd-or-npm rate-map

Search lockfiles for the bad versions.

grep -rnE "load-from-cwd-or-npm|rate-map" package-lock.json yarn.lock 2>/dev/null

What to do now

  1. Update purescript to 0.13.2 or later.
  2. Remove or update load-from-cwd-or-npm and rate-map so that no bad version remains.
  3. Reinstall dependencies from a clean lockfile.
  4. Treat package maintainer disputes as a risk signal. Pin versions and review dependency updates.

Vigilance compares the version you trust with a new one and reports the file that gained a new capability. See all attacks.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old load-from-cwd-or-npm-3.0.1 --new load-from-cwd-or-npm-3.0.2
files scanned: 64

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    index.js
           It now downloads from the internet. It did not before.

Frequently asked questions

What did the malicious PureScript npm packages do?

They sabotaged the PureScript installer so it hung during the prebuilt binary check. The sources do not describe data theft.

Which versions were malicious?

load-from-cwd-or-npm 3.0.2 and rate-map 1.0.3. Clean version 3.0.4 of load-from-cwd-or-npm followed on 9 July 2019.

Sources

  1. harry.garrood.me/blog/malicious-code-in-purescript-npm-installer/
  2. theregister.com/2019/07/15/purescripts_npm_installer/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free