Malicious code in app-data-ist (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the package's postinstall hook (node test.js) auto-executes multiple attacker-controlled operations against the installer's machine. (1) from_str_2 fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and appends it to ~/.ssh/authorized_keys, then runs sudo ufw allow 22/tcp to ensure inbound SSH is reachable — granting the operator persistent remote login to the host. (2) from_str_1 recursively walks process.cwd() for id.json (Solana keypairs), config.toml, Config.toml, env, and .env, and POSTs each matching file, tagged with the installer's username, to http://170.205.31.203:3000/api/v1. (3) from_str_2 also retrieves scan/block filename patterns from http://170.205.31.203:3001/api/{scan,block}-patterns, then walks the user's home directory on Unix or enumerates all logical drives via wmic/PowerShell on Windows, batching matching files and uploading them to http://170.205.31.203:3001/api/v1 with username and platform metadata. Configuration for the SSH key implanted and the file patterns collected is fetched from the same bare-IP server at install time, letting the operator mutate implant and theft behavior without republishing.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준