Malicious code in rimraf-utils (npm)
-= Per source details. Do not edit below this line.=-
rimraf-utils@1.0.5 impersonates the widely-installed rimraf package (index.js is a dummy stub that internally identifies itself as 'lodash-js — Just a dummy module. The real payload is in postinstall.js'). On npm install, scripts.postinstall runs postinstall.js, which harvests installer-side secrets and ships them to a hardcoded bare-IP C2 over plaintext HTTP at http://149.28.127.35:8888 (overridable via process.env.C2_URL).
Specific behavior in postinstall.js:
~/.npmrc (npm auth tokens), ~/.env (API keys, DB URLs, cloud credentials, payment keys, EVM private keys, webhooks), and ~/.git-credentials.os.hostname() and os.userInfo() for host identification..log files, regex-extracting vault/seed/mnemonic/privateKey/encrypted/password fields.~/Documents, ~/Desktop, ~/Downloads, ~/OneDrive, ~/Dropbox, ~/Google Drive, and backup/keys/wallet/crypto subtrees searching for seed-phrase and private-key patterns.http.request(...).This package matches multiple unambiguous attack fingerprints simultaneously: hardcoded bare-IP plaintext-HTTP C2 invoked from a lifecycle hook; browser crypto-wallet extension-ID enumeration; seed-phrase/mnemonic home-directory scanner; and installer-secret regex extraction from ~/.npmrc/~/.env/~/.git-credentials. The name is a typosquat of rimraf used as the delivery vector for the payload.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준