Malicious code in @qwedqwed/axios (npm)
-= Per source details. Do not edit below this line.=-
@qwedqwed/axios republishes the legitimate axios source verbatim under an unrelated scope, copies the original author metadata (Matt Zabriskie) for impersonation, and declares a dependency on @caspianph/storyteller (^1.0.0) that is not imported or referenced anywhere in the package's own code (dist/node/axios.cjs, lib/**). The phantom dependency serves no functional purpose for this package; its only effect is to be silently installed into the consumer's node_modules whenever this package is installed. The axios source itself is unmodified — the YARA hits on POST/fetch/ping are normal axios HTTP-client primitives, not C2 — so harm is delegated entirely to the unrelated transitive @caspianph/storyteller, which is the actual payload host. Installer harm: any developer fooled by the axios-lookalike scope ends up resolving and installing an attacker-controlled, unrelated package into their dependency tree.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준