Malicious code in env-fast (npm)
-= Per source details. Do not edit below this line.=-
env-fast@1.0.0 presents as a zero-dependency env loader but on require schedules a 72-hour-delayed activation that POSTs a host fingerprint (hostname, platform, release, arch, CPU/memory, homedir, network interface names, uptime, node version) to hardcoded bare-IP endpoint http://2.27.62.51:8080/api/health over plain HTTP, followed by a 6-hour heartbeat. The same payload probes installer secret locations — reports presence of ~/.npmrc, enumerates ~/.ssh for id_rsa/id_ed25519/id_ecdsa, and counts process.env keys matching /key|secret|token|password|auth|private|wallet|seed|mnemonic/i — and ships those results to the same remote endpoint. The 72-hour dormancy is a behavioral evasion pattern that avoids short-lived CI and sandbox environments while ensuring long-lived production hosts trigger the beacon.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준