Malicious code in verify-mycommand (npm)
-= Per source details. Do not edit below this line.=-
On npm install, postinstall.js executes whoami and id, collects host identity (hostname, platform, cwd) and CI metadata (CI, GITHUB_REPOSITORY, NODE_ENV environment variables), and beacons the data via HTTPS GET to a hardcoded Burp Collaborator subdomain md3zp4gf8gwxh437mjijacjbe2ky8pwe.oastify.com. A DNS lookup of <whoami>.<host> is also performed for out-of-band exfiltration. The package's own metadata describes it as a 'Security research canary' with a 'Takeover By lobo' marker, consistent with a dependency-confusion proof-of-concept or namespace hijack — but the install-time behavior is real exfiltration of installer identity and CI context to an attacker-controlled OAST endpoint regardless of stated intent. Any machine running npm install for this package leaks host and CI identifiers to a third party.
The OpenSSF Package Analysis project identified 'verify-mycommand' @ 2.0.4 (npm) as malicious.
It is considered malicious because:
The package communicates with a domain associated with malicious activity.
The package executes one or more commands associated with malicious behavior.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준