Malicious code in unifi-portal (npm)
-= Per source details. Do not edit below this line.=-
Package name unifi-portal shadows a presumed-private internal namespace and ships a preinstall: node index.js hook. On npm install, index.js (lines 4-5) performs a DNS resolve and HTTPS GET to d8hiivedv3ok8hrng5eghchyw4hwsioaz.oast.online — an interactsh/OAST collector controlled by a third party. The installer's source IP, resolver IP, hostname-derived subdomain label, and install timing are recorded by the collector without consent. The README self-describes as authorized security research against Ubiquiti's bug bounty, but the package is published to the public npm registry and any organization that resolves the name from public npm will be beaconed. The payload itself is a one-way phone-home (no env/credential scraping, no RCE), but the install-time outbound network to an attacker-shaped destination meets the supply-chain-attack threshold for a dependency-confusion squat.
The OpenSSF Package Analysis project identified 'unifi-portal' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준