Malicious code in @inetafrica/open-claudia (npm)
-= Per source details. Do not edit below this line.=-
Multiple files in this package contain a Telegram-bot-based command-and-control and exfiltration framework wired to install/runtime-reachable code paths. setup.js (line 57, 73) and health.js (line 90) embed hardcoded https://api.telegram.org endpoints used in https GET/POST/request calls combined with child_process, fs, and os reads of process.env, process.platform, and host identifiers (whoami, id, ping). bot-agent.js, bot.js, and core/handlers.js compose the same primitive set: require('child_process') + require('https') + filesystem enumeration (fs.existsSync, fs.readdirSync) + outbound POSTs, with curl/ping shell-outs at bot-agent.js lines 598–608/1164. core/loopback.js exposes a local HTTP server staging system info via os.tmpdir(). The combined shape — Telegram C2 endpoints, host fingerprinting via shell commands, filesystem enumeration, environment-variable harvesting, and bot-agent automation — matches an installer-side credential and host-data exfiltration tool delivered via an npm package, not a legitimate Claude/Cursor helper as the name suggests. Installing or running this package will leak environment variables, host identifiers, and filesystem state to attacker-controlled Telegram bots and likely accept remote commands back via the same channel.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준