Malicious code in zomato-config (npm)
-= Per source details. Do not edit below this line.=-
Dependency-confusion package targeting an internal Zomato namespace. The package ships only a stub index.js (module.exports = { name: 'zomato-config', version: '1.0.0' }) with no real functionality. Its package.json preinstall lifecycle hook runs curl to POST hostname, whoami, pwd, and the full process environment (base64-encoded via env | base64 -w0) to http://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7.oast.site/install/.... This fires automatically on npm install and leaks any environment-variable secrets present at install time (CI tokens, cloud credentials, npm/GitHub tokens) to an attacker-controlled out-of-band interaction host. The shape (empty payload + recon beacon to oast.site + internal-sounding name) matches a dependency-confusion reconnaissance / exfiltration package.
The OpenSSF Package Analysis project identified 'zomato-config' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준