Malicious code in markdown-editable-table (npm)
-= Per source details. Do not edit below this line.=-
The package's package.json declares a preinstall hook (node index.d.js) that runs automatically on npm install. The script in index.d.js base64-decodes a payload whose decoded body fetches JavaScript from https://everydaynodechecker-39143n.vercel.app/api/key?mem=root1 and passes the response to eval. Both the destination URL (hidden inside a base64 blob) and the eval identifier (reassembled from the char-code array [101,118,97,108] via String.fromCharCode and invoked as globalThis[tag](text)) are obfuscated. The package metadata (repository wooorm/markdown-table, description, funding) impersonates the legitimate markdown-table package while shipping unrelated code, indicating a typosquat lure. Installing the package results in arbitrary attacker-controlled JavaScript executing on the installer's machine.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준