Malicious code in chai-as-verified (npm)
-= Per source details. Do not edit below this line.=-
Package name typosquats chai-as-promised while its package.json advertises unrelated logger/vulnerability-management metadata. On require, index.js invokes a middleware() that spawns a detached node child process running lib/initializeCaller.js with stdio ignored and unref()'d. That child decodes a base64-hidden URL (https://tomato-brunhilda-40.tiiny.site/index.json) from a shadowed process.env object, fetches the JS response with a base64-decoded header name x-secret-key, and executes it via new Function.constructor("require", response)(require), granting the remote payload full Node require access. The C2 URL, header name, and header value are stored as base64 to hide them from static analysis.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준