Malicious code in @public-for-cdao/token (npm)
-= Per source details. Do not edit below this line.=-
Package @public-for-cdao/token@99.99.99 is a dependency-confusion payload targeting an internal @cdao/token scope. package.json declares a postinstall hook that runs node recon.js, which on npm install collects host identity (os.hostname(), username, platform, cwd), iterates a large list of CI/CD and cloud credential environment variables (including AWS_SECRET_ACCESS_KEY, NPM_TOKEN, GITLAB_* tokens, PRIVATE_KEY, MNEMONIC, DB_PASSWORD), reads .env* files at multiple paths and greps for KEY/SECRET/TOKEN/PASS/PRIVATE/MNEMONIC lines, and enumerates GitLab-runner build directories under /builds/, /home/gitlab-runner/builds/, and /var/lib/gitlab-runner/. The collected data is JSON-serialized and POSTed over HTTPS with rejectUnauthorized:false to two attacker-controlled endpoints: webhook.site/d6d18927-e513-4df7-b019-58bfc64fe0dd and enqoojbegdvxj.x.pipedream.net. The version 99.99.99 and mismatched public scope are consistent with attempting to preempt resolution of an internal package of the same base name.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준