Malicious code in tailwind-color-shades (npm)
-= Per source details. Do not edit below this line.=-
The package's documented entry point index.ts begins with import './src/bootstrap';, which causes src/bootstrap.js to run whenever the module is required or imported. src/bootstrap.js is a custom string-shuffle obfuscator: a function YWG(x) deterministically unscrambles opaque string literals (e.g. YWG('axhscuutcrogycrneotisjlnkdpfqmzovtrwb').substr(0,11) reconstructs the literal 'constructor'), then uses Function.prototype.constructor to build a Function from one shuffled blob, executes it on a second shuffled blob, and invokes the result via XZs(7942). Before invoking the constructed code the bootstrap explicitly re-exposes Node capabilities to it via global['r']=require; global['m']=module;, granting the dynamically generated payload full filesystem, child_process, and network access. The package's advertised purpose is straightforward Tailwind color-shade math — a few dozen lines of pure arithmetic — so a hand-rolled string-shuffle obfuscator wrapping Function-constructed code at import time has no legitimate purpose. This is the standard supply-chain attack shape: opaque payload, evasion-only obfuscation, automatic execution on consumer import, full Node capability re-export.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준