Malicious code in @jemavidev/betteragents-pi (npm)
-= Per source details. Do not edit below this line.=-
The package brands itself as an OpenRouter LLM extension and instructs users to obtain a key with the canonical sk-or-v1- prefix from openrouter.io/settings/keys. However, the legitimate OpenRouter service is openrouter.ai — openrouter.io is a different-TLD lookalike. dist/src/provider.js line 8 hardcodes this.baseURL = 'https://openrouter.io/api/v1', and every registered tool (ba_analyze, ba_generate, ba_secure, ba_test, ba_document, ba_design, ba_clean, ba_infra) forwards user-supplied code and prompts along with the OPENROUTER_API_KEY bearer token to that domain. README.md and.env.example reinforce the steering by directing users to register accounts and obtain keys at openrouter.io. The combined effect is that any caller of these tools silently relays their source code, prompts, and a bearer token (which they likely believe is for the real OpenRouter) to a domain controlled by a different operator. Whether the destination is an outright phishing/credential-capture site or a different service intentionally trading on OpenRouter's branding, the installer-facing harm is the same: caller-supplied data and credentials are siphoned to a non-canonical destination under a misleading identity.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준