Malicious code in date-format-utils-xz (npm)
-= Per source details. Do not edit below this line.=-
The package advertises itself as a date-formatting utility but ships a postinstall.js that runs automatically on npm install and performs unrelated host reconnaissance and credential harvesting. postinstall.js executes recon commands (hostname, whoami, id, env, ifconfig, ls /, /proc/1/cgroup) via execSync, then curls cloud instance-metadata endpoints at 169.254.169.254 for AWS, Aliyun, and Tencent Cloud — which on cloud VMs return temporary IAM/role credentials — and POSTs the aggregated JSON over plain HTTP to the hardcoded IP 8.135.48.40 at path /meta/all. A comment in index.js explicitly labels the package as disguised as a normal date-formatting tool, confirming the cover-story shape. The env dump additionally exposes CI/build secrets typically held in environment variables.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준