Malicious code in epic-internal-tools (npm)
-= Per source details. Do not edit below this line.=-
The package.json preinstall script auto-executes on npm install and performs installer-side reconnaissance and credential theft. It collects os.hostname(), username, cwd, platform, node version, npm user-agent, and CI indicators (GITHUB_ACTIONS, JENKINS_URL, TEAMCITY_VERSION, HORDE_AGENT), then enumerates process.env and selects up to 30 variables matching credential-shaped patterns (AWS_, GITHUB_, GH_, NPM_, EPIC_, UE_, HORDE_, P4, CI, BUILD, TOKEN, KEY, SECRET). The collected JSON is POSTed over plain HTTP to a hardcoded bare-IP endpoint at http://109.123.247.172/npm/epic_internal_tools. In parallel, it performs a DNS lookup against -.epic_internal_tools.npm.epic-dc.oast.fun, using an interactsh-style out-of-band collector to smuggle host and user identifiers via DNS as a covert channel that bypasses HTTP egress filtering. The package name epic-internal-tools, the sentinel version 99999.0.0, and the Epic/Unreal/Horde/Perforce env-var targeting are the standard dependency-confusion pattern aimed at Epic Games internal build agents. Installing this package on a developer workstation or CI runner ships CI/cloud/registry credentials and host identity to attacker infrastructure.
The OpenSSF Package Analysis project identified 'epic-internal-tools' @ 99999.0.0 (npm) as malicious.
It is considered malicious because:
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준