Malicious code in nodeaxois (npm)
-= Per source details. Do not edit below this line.=-
The package declares scripts.postinstall: node.init.js, which runs automatically on npm install. The.init.js script collects host metadata (os.hostname(), os.platform(), process.cwd(), process.pid, timestamp), enumerates approximately 60 credential-shaped environment variables (NPM_TOKEN, GITHUB_TOKEN, AWS_SECRET_ACCESS_KEY, STRIPE_, DOCKER_, CLOUDFLARE_, GCP, etc.), reads ~/.npmrc, ~/.env, ~/config.json, ~/credentials.json, and files under ~/.config/ whose names contain token/cred/secret, and POSTs the aggregated JSON to a hardcoded https://webhook.cool/at/tender-deer-80/ endpoint. The package's index.js exports an empty object; the tarball provides no legitimate functionality. The name is a likely typosquat of axios.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준