Malicious code in @nolimit-x/win32-x64 (npm)
-= Per source details. Do not edit below this line.=-
Package ships a single 8.1 MB Windows PE (nolimit-core.exe) as its main entry with only the description 'nolimit-x native binary for Windows x64' — no README, no source, no documentation of what the binary does. String analysis of the binary reveals SMTP bulk-mailer / SMTP-credential-checker function-name fingerprints (send_emails, prime_smtps, smtp_configs, shared_body, first_chunk, chunk_offset, successful, all_dead, </script>) consistent with abuse tooling that iterates SMTP credential lists and sends bulk mail. Reversed-string obfuscation tokens (setybdet → tedbytes, uespemos → someseu/somespeu, arenegyl → lygenera, modnarod → dorandom) indicate the binary deliberately hides string constants from casual inspection. The package is a platform-shard (win32-x64) intended to be consumed by a parent @nolimit-x package that will spawn the binary on the installer's machine; the binary's purpose does not match any legitimate library function and is undocumented. Doc-mismatch + opaque obfuscated binary + SMTP-abuse string fingerprints together indicate a hostile payload distributed via npm.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준