Malicious code in gmail-changer (npm)
-= Per source details. Do not edit below this line.=-
Package exports a complete Gmail account-hijack pipeline driven by stolen session cookies. Exported helpers (waitForRemoveRecovery, waitForRecoveryAdd, waitForPasswordChange, waitForDeviceLogout, waitForTwoFaActive, waitForNameChange) automate, in sequence: removing the victim's recovery phone number, injecting an attacker-controlled recovery email at the hardcoded domain @oletters.com, resetting the password to a random string, signing every other device out, harvesting 2FA seed + backup codes, and changing the display name. OTP interception is wired to a hardcoded SMS-rental endpoint at sever1.tempxapi.com/api/sms, where the package polls for incoming Google verification codes (G-\d{6}) using an X-Integrity-Token to drive recovery-number swaps and login challenges. index.js getMailYear additionally POSTs to Gmail's undocumented sync RPC at mail.google.com/sync/u/0/i/bv with stolen cookies to enumerate the victim's ^all mailbox (up to 2000 messages per page) for post-takeover reconnaissance. Puppeteer is launched with puppeteer-extra-plugin-stealth, --ignore-certificate-errors, and request interception that silently swallows Gmail's SetOSID redirect (replaced with a 200 OK stub) to harvest the session without completing the page transition. Every advertised API mutates a Google account against its owner's interests; there is no legitimate use case. Installing or loading this package equips the installer with — and contributes to a public ecosystem of — operational account-takeover tooling, with a hardcoded attacker drop-domain (@oletters.com) and third-party OTP relay baked in.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준