Malicious code in @qlab/component-intelligence (npm)
-= Per source details. Do not edit below this line.=-
package.json declares a preinstall hook ("preinstall": "node index.js") that fires automatically on npm install. index.js requires os, dns, https, querystring, and the package's own package.json, then collects the installer's hostname (os.hostname()), username (os.userInfo().username), home directory (os.homedir()), configured DNS servers (dns.getServers()), current working directory, and the full contents of package.json, and POSTs them via HTTPS to the hardcoded webhook https://eo1e4fhn1i67p8r.m.pipedream.net/. This is the canonical dependency-confusion / recon-beacon shape: host identifiers and internal package metadata leave the machine unconditionally at install time to an attacker-controlled endpoint, giving the attacker reconnaissance data on internal package names, corporate hostnames, and user identities to fuel follow-on supply-chain attacks.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준