Malicious code in @solana-labs/web3js (npm)
-= Per source details. Do not edit below this line.=-
This package impersonates the legitimate @solana/web3.js library under a confusable scope (@solana-labs/web3js). On npm install, the postinstall hook executes install.js, which loads os, child_process, fs, and https, collects host identifiers via os.hostname() and os.userInfo() along with process.platform, probes filesystem paths via fs.existsSync(...), and issues HTTPS POST requests carrying the harvested information. install.js also invokes execSync('powershell...') and execSync('curl...') to run shell commands fetched/triggered at install time. A reference to http://www.apple.com appears alongside the exfiltration code, consistent with connectivity-check or decoy behavior. The combination of name-squat against a widely used Solana library, automatic execution at install via postinstall, host enumeration, and shell execution constitutes an installer-targeted supply-chain attack.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준