Malicious code in uidai_reusable_components (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the preinstall lifecycle script in package.json executes an inline Node one-liner that collects the installer's hostname, OS username, NODE_ENV, current working directory, local IPv4 addresses (via ipconfig|findstr IPv4 on Windows or hostname -I on Linux), the configured npm registry URL (npm config get registry), and Windows USERDOMAIN / Unix id output. The collected data is URL-encoded and embedded as a subdomain label in an HTTP GET to *.d8ofndiplbq1d996mde0a9yukto9dm49e.oast.online, an Interactsh out-of-band callback host controlled by the package author. The package's own description states it is a 'PoC for dependency confusion' targeting the UIDAI (Aadhaar / India's national identity authority) internal namespace, and the harvested private npm registry URL is the canonical signal an attacker uses to confirm a dependency-confusion victim. The package ships no actual UI component functionality — its only effect on install is the exfiltration beacon.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준