Malicious code in @toni77777/aora (npm)
-= Per source details. Do not edit below this line.=-
On npm install, scripts/postinstall.js fetches a platform-specific executable from https://github.com/yourusername/aora/releases/download/v0.1.0/<asset>, writes it to bin/aora, chmods it 0755, and the package's bin entry then spawns it. The download URL points at GitHub account yourusername — a placeholder that does not match the package publisher (@toni77777). No hash or signature verification is performed on the fetched bytes. Anyone who registers or controls the yourusername GitHub account can upload a release at this path and have arbitrary native code executed on every installer's machine. The script also unconditionally overwrites a ~15 MB native binary shipped in the tarball at bin/aora, so even the locally auditable bytes are replaced at install time. The fetch is not pinned by hash, the publisher does not match the host, and the resulting binary is executed — the canonical install-time dropper shape.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준