Malicious code in consumerweb-authflow (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the package's postinstall.js collects host identifiers via os.hostname(), os.userInfo().username, os.platform(), and the current working directory, then POSTs them over HTTPS to kd1tbfhej84bcqde44rq77o79yfp3gr5.oastify.com (a Burp Collaborator out-of-band callback subdomain). The package's own metadata self-identifies as a dependency-confusion proof-of-concept (description: "Dependency confusion PoC - H1-lingtys", payload tag src: 'paypal-dep-confusion-poc'), and the package name is chosen to collide with an internal/private package name so that misconfigured resolvers pull this public version instead. Regardless of bug-bounty intent, every installer's machine identity is leaked to an external attacker-controlled OAST endpoint without consent, automatically, on a default install.
The OpenSSF Package Analysis project identified 'consumerweb-authflow' @ 4.1.1 (npm) as malicious.
It is considered malicious because:
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준