Malicious code in uipath-sugar-sell (npm)
-= Per source details. Do not edit below this line.=-
Package uipath-sugar-sell@99.9.1 exhibits the canonical dependency-confusion shape: an internal-sounding name targeting a UiPath/SugarSell namespace, a 99.9.1 version overshoot designed to win semver resolution against any private registry, an empty index.js (module.exports = {}) so the package provides no actual functionality, and a single dependency ltidisafe declared as a direct URL https://ltidi.storage.googleapis.com/depenconf/ltidisafe-2.7.8.tgz. The path segment depenconf is explicit naming of the dependency-confusion technique. Installing this package causes npm to fetch and install the off-registry tarball from the Google Cloud Storage bucket, bypassing the public registry's audit surface; any lifecycle scripts in that tarball execute on the installer's machine at npm install time, and the tarball contents are mutable by whoever controls the bucket.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준