Malicious code in wml-core (npm)
-= Per source details. Do not edit below this line.=-
wml-core@99.0.1 is a dependency-confusion package targeting an internal wml-* namespace, published with an inflated version (99.0.1) to win npm resolution against an internal package of the same name. The preinstall script poc.js runs automatically on npm install and harvests: hostname, username, OS/platform info, full network configuration (ipconfig /all on Windows or ip a + /etc/resolv.conf on Linux), whoami /all / id output, git remote URLs, the parent project's package.json, CI configuration files (.gitlab-ci.yml, .github/workflows/*, Jenkinsfile, azure-pipelines.yml), and a filtered dump of process.env matching credential-bearing prefixes including TOKEN, AWS, AZURE, NPM, GITHUB, GITLAB, JENKINS, WALMART, WMT, CI_. The collected JSON blob is POSTed to d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me (an Interactsh out-of-band callback host) over HTTPS, with a DNS callback emitted as a side channel. Any installer outside the intended target scope — including unintended internal builds and any third party who installs this name — has their build environment, CI secrets, and cloud/registry tokens exfiltrated. The package's self-description as 'authorized bug bounty research' does not change installer-side harm: the payload fires unconditionally on any npm install.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준