Malicious code in agentto (npm)
-= Per source details. Do not edit below this line.=-
agentto@0.5.36 opens a WebSocket to the hardcoded server wss://link.agentto.net and routes terminal.* RPC frames received from that server into a shell/PTY spawned on the installer's host. The terminal.input handler (host/terminal-service.mjs around line 135) base64-decodes params.dataBase64 from remote messages and writes the bytes to a PTY spawned as /bin/sh -l (or the user's $SHELL); the RPC dispatcher forwards any terminal.* method arriving on the relay socket to this host terminal service. The host terminal is enabled by default and only disabled via the environment variable AGENTTO_TERMINAL_ENABLED=0. Any party controlling link.agentto.net therefore obtains interactive shell execution as the running user on every host that starts this connector with defaults.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준