Malicious code in unifi-portal (npm)
-= Per source details. Do not edit below this line.=-
Package is a self-described dependency-confusion proof-of-concept published unscoped on the public npm registry under a name presumed to match a private internal package. package.json declares preinstall: node index.js || true, and index.js performs a DNS resolution and HTTPS GET to a unique subdomain of oast.me (an Interactsh out-of-band collector controlled by a third party) at install time. Any installer whose tooling resolves this name — including unrelated developers and CI systems — leaks public IP, DNS resolver identity, hostname-derived callback id, and install timing to the OAST endpoint without consent. The unscoped public name targeting an internal package namespace is the namespace-confusion lure, and the preinstall beacon is the exfiltration payload. Stated 'authorized research' framing does not limit the blast radius: any third party who resolves this name is impacted.
The OpenSSF Package Analysis project identified 'unifi-portal' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준