Sonatype Nexus Repository warns "1 Malware Component Found" - Sonatype Nexus Repository - Sonatype Community

Sonatype Nexus Repository warns “1 Malware Component Found”

post by izaak on Oct 23, 2024

Izaak van Niekerk

Since upgrading our free local standalone version of Nexus Repository to version 3.73.0, we are seeing a Big Red Warning stating 1 Malware Component Found.

From the guide below, my understanding is that we would need the Sonatype Repository Firewall in order to remove the malware. I assume this means that we would need to upgrade Nexus to the paid for, Pro version.

https://help.sonatype.com/en/guide-to-removing-malware.html

Is there a different way to remove the malware? Perhaps somebody could suggest another “free” route that we could take?

post by mfrost on Oct 23, 2024

Hi @izaak!

Sounds like you’ve already clicked the Contact Sonatype button on the banner to be directed to our dedicated Malware support page.

Someone from our account management team will reach out to answer any questions you may have, and discuss options.

Let me know if you don’t get in touch with someone.

post by fredrik on Oct 31, 2024

We have the same issue and want to resolve it without contacting sales and buying more products.

Are there any way to remove this (commercial) banner in the OSS-version of Nexus repo?

post by mfrost on Nov 1, 2024

Hi @fredrik!

Thanks for reaching out and sharing your concerns around our new malware banner feature.

We view malware in any of our customer’s environments whether it be our free or paid repository as a very serious and active threat that needs to be addressed as soon as possible.

We are committed to supporting the safe development of software and therefore want to ensure you are aware of when malware is present. The malware must be removed in order for the banner to no longer be present.

If you’re looking for self-guided support, you can review our free online resources here to learn more about how best to secure your environments.

Please reach out if you would like further support.

Many thanks!

post by fredrik on Nov 4, 2024

Ok. So how do I find the infected files so I can take action upon them?

post by mfrost on Nov 4, 2024

The best way to identify and remove malware using a Sonatype-supported solution is to use Sonatype Repository Firewall. With Sonatype Nexus Repository Manager Pro, it allows you to see the risk of components in individual proxy repos, but it does not specify whether or not a component is malicious.

post by fredrik on Nov 5, 2024

How do I find it in the OSS-version of Nexus repository?

post by christoph.keller on Nov 5, 2024

Hi all,

I have the same issue, already contacted sonatype and just got the answer that I should buy the repository firewall. But as small company, this is no option at all.

But I got no info about how I can find out the exact package or the exact file that is affected.

I also tried checking each package using ClamAV, without any match (so it seems that there is no malware in the packages).

This sounds more like a sales-banner than a helpful information…

So sonatype, please either tell us how we find out the infected package or file name, or provide us how you checked the packages to find the infected one (to manually reproduce the result), or just remove the unusable big red sales-banner.

Thank you and have a great day,

Chris

post by d.remke on Nov 6, 2024

Hello, this message is now also appearing for me and is unsettling my colleagues. It can’t be the solution that I have to buy the nexus firewall so that I can determine the affected components. Even if the solution would perhaps help us to manage our artifacts better, I am currently lacking the arguments to get a budget for it. I would need to know what is affected in order to assess the risk.

post by mfrost on Nov 7, 2024

@christoph.keller The banner indicates that open source malware is present within your proxy repos. This open source malware will not be detected with an anti-virus tool.

If you’re looking to take action within OSS, you could re-consider proxying high-risk ecosystems and delete those proxy repos. You run the risk of breaking builds if you do this but it is an option.

Even with removing those proxy repos, having open source malware at all is very risky as you know.

The only Sonatype-supported way to accurately identify, block, and remediate malware is through Sonatype Repository Firewall. Firewall is supported by our best-in-class malware identification capabilities. You can also learn more about our data and intelligence here.

post by christoph.keller on Nov 8, 2024

@mfrost thank you for your message.

I know what this banner is trying to tell me. But it is just a worthless big red danger-sign, as long as it does not tell me what package is affected.

Technically, either nexus exactly knows what package is affected and just will not tell me until I pay for, or otherwise it shows just a random number.

I already spent 8+ hours to build a pipeline that checks the npm-proxy-repository for malware and viruses (using ClamAV), checked each package and specific version, if it is still listed on npmjs.org, without any luck. All packages seems legit.

So could you please tell me either the name of the affected package, or the method how the packages are scanned to find the affected one?

And about the „proxying high-risk ecosystems“, i am using the official npmjs.org feed. So nothing inofficial or high-risk at all, I just want a convenient single package-source for both our own npm-packages and the official ones. Just to make our developers life a bit easier.

Thank you for your answers and have a great day,

Chris

post by sebastien_picavet on Nov 8, 2024

Same here.

This banner sounds like an advertisement. Like many tools/scams how warn users about malwares/virus on theirs computers.

The form is not very good. The only way to get rid of this message is to pay. We should be able to deactivate it or Nexus should name the components.

Paid business model could be: OSS = warn/show components (passive) / Pro = actively block components to be downloaded (active).

It sounds more fair and less commercial.

Kind regards

post by bjorns on Nov 8, 2024

Make sure none of your packages are listed in GitHub Advisory Database · GitHub this was the case with someone I know who experienced this notification.

post by christoph.keller on Nov 12, 2024

Hi @mfrost,

Are there any news on this issue? Is there any way to get rid of the banner, without buying the Repository Firewall?

Thank you for your help.

Best regards and have a great day,

Chris

post by mfrost on Nov 12, 2024

@christoph.keller, thanks for checking back in. If you click on the banner, it will take you to an updated page that includes some new resources as of Monday, including an FAQ guide that answers these questions.

post by christoph.keller on Nov 13, 2024

For all that suffer from this malware-notification:

I found out that it is (perhaps) possible to disable this, by adding the following lines to the /nexus-data/etc/nexus.properties file (in case of a docker-installation):

nexus.malware.risk.enabled=false
nexus.malware.risk.on.disk.enabled=false

WARNING: This just disables the malware-warning banner and DOES NOT FIX the malware components (if any).

Can anyone confirm that this removes the banner? According the source, this should be the feature-flag for this.

Hope that helps anyone, that searches a way to disable this warning.

post by izaak on Nov 15, 2024

Thank you Chris. This was very helpful and I can confirm that it removed the banner for us.

post by youngtristanza on Nov 15, 2024

Thank you for the help Christoph. I was able to remove the banner using the method you described.

post by sebastien_picavet on Nov 26, 2024

On our side, we have identified: Malware in fsevents · GHSA-xv2f-5jw4-v95m · GitHub Advisory Database · GitHub

Our malwares are all NPM/fsevents things.

Nexus gets its data from https://rhc.sonatype.com/rest/rhc/extras/maliciousContent/{NEXUS_ID} (can be finded on logs) => it allows to identify the registry.

Then, we have scraped malware databases of GitHub: GitHub Advisory Database · GitHub

And for each entry, we have used Nexus API to check if we have one: https://it-dev-fr-nexus.intramatch.eu:8080/service/rest/v1/search?repository=npm-registry&name={MALWARE_COMPONENT}.

= ~ 50 were identified (among 18000).

Finally, we have checked group/version one by one to identify fsevents.

post by christoph.keller on Dec 4, 2024

Follow-up for this topic:

The recently released version 3.75.0 release introduces a dismiss button for the malware-banner. Thank you, Sonatype, for listening to our feedback!

Details here: https://help.sonatype.com/en/sonatype-nexus-repository-3-75-0-release-notes.html#dismiss-the-malware-risk-banner-during-your-session