Malicious code in fpjson-lang (npm)
-= Per source details. Do not edit below this line.=-
package.json declares "preinstall": "./bin/install-deps", causing npm to execute a ~954KB packed Linux ELF binary on every install. The package advertises itself as a tiny JSON-based functional language built on Ramda, and the actual library at dist/cjs/index.js is ~1.8KB of pure JavaScript with no native dependency — there is no legitimate reason for a native install helper. Strings extracted from the shipped binary include HTTP/1.1, POST/DELETE verbs, GitHub API version 2022-11-28, USERPROFILE, TLS/crypto primitives (RSA_PKCS1_, Ed25519), PTRACE, and LIBBPF_0.0 — a feature set (HTTP client + GitHub API + ptrace + crypto) wholly unrelated to a JSON parser. The binary is packed and opaque to static review. The combination of (a) auto-execution at install time via preinstall, (b) shipped opaque native binary, (c) capability set entirely unrelated to the package's declared purpose, and (d) absent source/build manifest matches the install-time dropper pattern: arbitrary attacker-controlled code runs on every installer's machine on npm install.
This package was compromised as part of the IronWorm campaign. This campaign executes a malicious binary payload during installation via a preinstall hook. The payload is a Rust-built infostealer that targets developer environments, scanning for and harvesting credentials related to cloud providers, object storage, databases, source-control, package registries, and AI developer tools. It also targets cryptocurrency wallets, specifically injecting a malicious JavaScript hook into the Exodus desktop wallet to capture passwords and recovery phrases. Furthermore, the malware exhibits worm-like behavior by stealing GitHub and NPM credentials to push malicious updates to the victim's repositories and publish trojanized packages, and it uses an eBPF-based kernel rootkit to hide its processes and network connections on Linux systems.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준