Malicious code in nw-demo (npm)
-= Per source details. Do not edit below this line.=-
Package is published publicly on npm at version 100.20.33 — a version-number shape used in dependency-confusion attacks to outrank private internal packages of the same name. The package.json claims authorship by 'Atlassian Ecosystem Engineering' and describes itself as an 'Atlassian internal demonstration and utility framework', but the package is published to the public registry under no Atlassian-owned scope. The main entry index.js contains only try { require('nw-demo-utils'); } catch (e) { } — its sole behavior on import is to silently load and execute a separately-published transitive dependency (nw-demo-utils ^1.0.16), with errors swallowed to hide failures. The README instructs consumers to require('nw-demo'), which transitively executes nw-demo-utils' module-load code in the installer's process. The wrapper itself ships no payload; it functions as a loader that laundries arbitrary code from nw-demo-utils into any pipeline that mistakenly resolves the public package over a private internal one.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준