Malicious code in nolimit-x (npm)
-= Per source details. Do not edit below this line.=-
The package places 40+ heavily obfuscated JavaScript files (_0xNNNNNN hex-mangled identifiers throughout) inside a hidden .ad/ directory at the tarball root. File names include phone-validator.js, sms-providers.js, smtp-health-cache.js, web-command.js, and a sequential set x0.js through xz.js. The combination of (a) a hidden .ad/ directory designed to evade casual inspection, (b) uniform heavy obfuscation across every shipped module, and (c) module names referencing SMS providers, SMTP health caching, phone validation, and a web-command controller is consistent with a bulk-messaging / spam-relay / abuse-toolkit payload bundled into an npm package. There is no legitimate engineering reason to ship a library's entire functionality as obfuscated bundles under a dotfile directory; this pattern exists specifically to defeat code review and registry scanning. Installers who add this package gain a large attacker-controlled obfuscated codebase that cannot be audited and whose web-command module name suggests remote command/control of installer behavior.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준