Malicious code in testnpmnmp (npm)
-= Per source details. Do not edit below this line.=-
package.json declares "preinstall": "./scripts/postbuild", where scripts/postbuild is a 976,568-byte unsigned, unhashed, unversioned Linux ELF executable shipped in the tarball. The package's only JavaScript source (src/index.js) is a trivial stub that exports () => { console.log("hello") }, with the bundled output (dist/index.cjs.js) matching. Nothing in the package's stated Arweave/Warp-contracts wrapper purpose justifies a native executable, and the binary's embedded strings (LIBBPF_0.0, PTRACE, NETLINK, HTTP/1.1, USERPROFILE, RSA_PKCS1_, Ed25519) indicate credential-handling and network-agent capabilities rather than build tooling. On npm install, the binary runs with the installer's privileges before any user inspection; the JS stub is a cover for shipping and executing arbitrary native code. The package name testnpmnmp and stub source further indicate a throwaway dropper rather than a real library.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준