Malicious code in intl-ad-routing (npm)
-= Per source details. Do not edit below this line.=-
intl-ad-routing@99.0.1 is a dependency-confusion squat targeting an internal @livingdesign/react namespace. On npm install, the package's preinstall hook (poc.js) executes shell commands to enumerate the installer's environment (ipconfig /all on Windows, ip a && cat /etc/resolv.conf on Linux) and collects hostname, username, install directory, network interfaces, the full list of process.env keys, and every npm_* environment variable (which can include npm registry auth tokens / _authToken values). The collected JSON is POSTed over HTTPS to d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me (an interactsh out-of-band collector), and a DNS callback encoding hostname+username is also issued. The package's own description states it is a 'Dependency Confusion PoC' for a bug-bounty program, but the lifecycle code runs on any installer that resolves this public version in place of the intended private package — without the installer's consent — and ships their host identifiers and potentially registry credentials to a third-party collector.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준