Malicious code in zod-pino444 (npm)
-= Per source details. Do not edit below this line.=-
The package name mimics the popular zod and pino libraries but its shipped code implements a credential-harvest and relay pipeline that fires on install. scripts/postinstall-agent.mjs runs as a postinstall lifecycle hook, performing host reconnaissance (ping/GET/id) before invoking the bundled agent modules under dist/. dist/discordRelayUpload.js POSTs collected data to Discord relay endpoints (with base64-encoded payload construction and network reconnaissance on lines 39, 227, 306, 321, 398). dist/secretScan/agentStartupAudit.js and dist/secretScan/contentScanner.js scan for secrets and exfiltrate them via fetch calls to https://huggingface.co endpoints (lines 490, 508, 563). dist/hfCredentials.js and dist/deploymentDefaults.js decode base64-embedded configuration/credentials at load time. The typosquat-style name, obfuscated base64 payloads across multiple modules, install-time execution, and hardcoded exfiltration destinations together match the active-attack fingerprint (credential collection + hardcoded C2 + install-time auto-execution). The safety filter withheld traced-code output for this package, consistent with operational malware content.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준