Malicious code in @public-for-cdao/common (npm)
-= Per source details. Do not edit below this line.=-
Package declares a postinstall hook that runs recon.js on npm install. recon.js reads a broad list of secret-bearing environment variables (AWS_SECRET_ACCESS_KEY, NPM_TOKEN, SSH_PRIVATE_KEY, MNEMONIC, GitLab and CI_* tokens, DB/Redis passwords) and scans common.env file paths including /root/.env, /app/.env, and /home/gitlab-runner/.env for KEY/SECRET/TOKEN/PASS/PRIVATE/MNEMONIC matches. The harvested payload plus host identifiers is POSTed to two hardcoded non-first-party endpoints, webhook.site/d6d18927-e513-4df7-b019-58bfc64fe0dd and enqoojbegdvxj.x.pipedream.net, over HTTPS with certificate verification disabled (rejectUnauthorized:false). The package is published at version 99.99.99 under the public scope @public-for-cdao while index.js identifies itself as @cdao/common, and a source comment self-labels it a 'CryptoDAO Dependency Confusion Reconnaissance Payload' — the shape of a dependency-confusion attack against CI/CD builds that misroute an internal @cdao scope to the public registry.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준