Malicious code in zomato-sushi (npm)
-= Per source details. Do not edit below this line.=-
package.json declares a preinstall script that runs curl with form-encoded fields carrying the installer's hostname (hostname -f), whoami, current working directory, and a base64-encoded dump of the entire process environment (env | base64 -w0) over plain HTTP to an Interactsh/OAST out-of-band collector at d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7.oast.site. A preuninstall hook beacons the same host. This fires automatically on npm install with no user opt-in. The bulk environment dump captures any secrets present in the shell at install time, including CI tokens, NPM_TOKEN, AWS_* keys, and similar credentials. The package name mimics Zomato's design system namespace and the shipped index.js is a stub with no functionality, consistent with a reconnaissance/credential-capture lure rather than a real library.
The OpenSSF Package Analysis project identified 'zomato-sushi' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준