Malicious code in ohcm-culture-formatting (npm)
-= Per source details. Do not edit below this line.=-
ohcm-culture-formatting@5.0.0 declares a preinstall hook ("preinstall": "node index.js") that auto-executes on npm install. index.js uses child_process.exec to run a shell pipeline that reads /etc/passwd, /etc/hosts, /etc/shadow, and id output, base64-encodes the concatenation, and POSTs it via curl to http://d98fu4tmls2g936th9qgfxje1qj9g91a6.oast.fun/ohcm-culture-formatting/$(whoami)/$(hostname)/, embedding the installer's username and hostname in the URL path and the file contents in the User-Agent header. The destination is an Interactsh/OAST out-of-band interaction collector. The package name mimics an internal ADP/Lifion (ohcm-*) namespace and the description string is Lifion host, consistent with a dependency-confusion payload targeting that internal namespace.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준