Malicious code in @access-risk/browser-remedy-react (npm)
-= Per source details. Do not edit below this line.=-
On npm install, postinstall.js executes automatically and collects host identity and environment details using os.hostname(), process.cwd(), and filesystem reads, base64-encodes the data via Buffer.from(...).toString('base64'), and exfiltrates it through both DNS lookups (require('dns')) and HTTPS requests (require('https')). The dual-channel base64 exfiltration shape (DNS tunneling plus HTTPS POST) combined with collection of system identifiers is the canonical install-time data-theft fingerprint and provides direct attacker benefit: any machine running npm install for this package leaks identifying information to an external destination automatically, before the user has reviewed any package code.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준