Malicious code in ai3 (npm)
-= Per source details. Do not edit below this line.=-
package.json declares "preinstall": "./.github/scripts/precheck", which points at a 976,568-byte precompiled Linux ELF x86-64 binary shipped inside the tarball with no source, no build script, no binding.gyp, and no documentation. On npm install the binary runs automatically with the installer's privileges. Extracted strings show HTTP client code (HTTP/1.1, POST, Host:), full TLS/crypto stacks (RSA_PKCS1_, Ed25519, MLKEM, X448), and GitHub API fingerprints — consistent with a network-capable dropper / credential harvester rather than a legitimate native addon. The payload is staged under .github/scripts/ (a directory normally reserved for non-executing GitHub Actions workflow files) and named precheck with no extension, both consistent with deliberate concealment from reviewers. Package metadata is empty (description: "", author: ""). Installing this package runs attacker-controlled compiled code on the installer's machine.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준