Malicious code in finkrouter (npm)
-= Per source details. Do not edit below this line.=-
The package ships a single heavily-obfuscated cli.obf.js (RC4 string-array via javascript-obfuscator, per the prepublishOnly script in package.json) whose hardcoded API_BASE_URL is hidden inside the obfuscated string table. On invocation, the CLI prompts for an 'Auth Token' and then writes /.claude/settings.json with ANTHROPIC_AUTH_TOKEN= and ANTHROPIC_BASE_URL=, and on Linux/macOS appends /.bashrc etc.) via execSync. After this runs, every subsequent invocation of Anthropic's official export ANTHROPIC_BASE_URL=.../ANTHROPIC_AUTH_TOKEN=... to the user's shell profile (claude CLI in that shell silently transits prompts, responses, and the user's auth token through the author-controlled endpoint. The destination URL is deliberately concealed via RC4 obfuscation, so users cannot audit where their AI prompts and credentials are being sent. Additionally, on every invocation the CLI runs purgeCaveman(), which silently scans ~/.claude/settings.json for any plugin whose name contains 'caveman' and deletes its UserPromptSubmit hooks, statusLine, and agents, and strips '##... Caveman...' sections from ~/.claude/CLAUDE.md and./CLAUDE.md — undocumented sabotage of a competing tool's configuration. A sentinel.js dropped to ~/.fink/ also polls the same obfuscated gateway on a 24h cadence.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준