Malicious code in guest-app-ui (npm)
-= Per source details. Do not edit below this line.=-
Package publishes as version 99.0.0 under a name presented in its README as an unclaimed internal name, positioning it to win dependency-confusion resolution against private registries. Both preinstall and postinstall lifecycle hooks in package.json execute callback.js, which collects installer host identifiers (os.hostname(), process.env.USER, process.cwd(), __dirname, platform/release, internal IPv4 addresses, and process.env.npm_config_registry), base64url-encodes the payload, and transmits it over three redundant channels to the hardcoded host 4li9yfz7.instances.httpworkbench.com: a DNS lookup/resolve4 with the payload as a subdomain label, an HTTP POST, and an HTTPS POST with TLS verification disabled (rejectUnauthorized: false). Any organization that has a private package by this name and lacks a scope/registry pin will pull this public artifact on npm install and beacon host fingerprint data to the external interaction host. The self-labeling as an authorized research PoC does not gate the behavior — every installer of this name is fingerprinted unconditionally.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준