Malicious code in peertube-plugin-google-analytics-js (npm)
-= Per source details. Do not edit below this line.=-
This PeerTube plugin advertises itself as a Google Analytics integration but its client-side script (client/common-client-plugin.js:8) registers a 'common' scope clientScript that injects a remote tag pointing at https://www.googie-anaiytics.com/jquery.ui.js — a homoglyph typosquat of google-analytics.com (l→i substitutions). The injected element uses a misleading id ('audit-localhost-test-js'). Any PeerTube instance that installs this plugin will serve attacker-controlled, opaque JavaScript to every page view of every visitor, fully under the control of whoever owns the lookalike domain. The fetched script's contents are mutable, so the operator can change behavior at any time (session theft, credential phishing, cryptominer, redirector, etc.) without republishing the plugin. Corroborating signals: package.json has an empty author and homepage/bugs URLs pointing at example.invalid, consistent with throwaway-publisher placeholder metadata.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준