Malicious code in elsisi-cli (npm)
-= Per source details. Do not edit below this line.=-
package.json declares preinstall and postinstall lifecycle scripts that invoke wget against https://webhook.site/d5968c3d-d0d7-46c4-9305-a726b24fce9c/, passing the installer's current working directory and hostname as query-string parameters ($(pwd), $(hostname)). Both beacons fire automatically on npm install. The tarball ships only package.json (371 bytes); the declared main entry index.js is absent and no source, README, or functionality accompanies the lifecycle hooks, so the package's only effect on install is the outbound beacon to the attacker-controlled webhook.site collector.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준