Malicious code in power-platform-playwright-toolkit (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the package's postinstall script (postinstall.js) collects host identifiers and CI context — whoami, os.hostname(), os.platform(), cwd, CI, GITHUB_REPOSITORY, NODE_ENV — and sends them off the installer's machine via two channels: an HTTPS GET to 6v2j7oyzq0ehzolr4303sw1vwm2gqje8.oastify.com (a Burp Collaborator out-of-band callback host) at path /microsft?<querystring>, and a DNS lookup of <whoami>.6v2j7oyzq0ehzolr4303sw1vwm2gqje8.oastify.com to leak the username via DNS even when HTTPS egress is blocked. The package name impersonates Microsoft's Power Platform Playwright tooling namespace, and the exfil path token microsft (note the misspelling) serves as a campaign tag. The script self-describes as a 'security research canary' / 'Takeover By lobo', but installers have not consented to off-host data transmission and the captured data (GitHub repository identifier, CI flag, hostname, username) is direct reconnaissance value to whoever controls the OAST subdomain.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준