Malicious code in bolt-delivery-menu-app (npm)
-= Per source details. Do not edit below this line.=-
Package executes a DNS-based beacon at both install time (package.json scripts.install runs node index.js) and on every require() of the module. lib/core.js reads os.userInfo().username, os.hostname(), and process.cwd(), concatenates them with a campaign tag into a single label, and triggers dns.resolve4 against that label under the attacker-controlled domain oob.sl4x0.xyz, leaking installer host identity over DNS (a channel chosen to bypass HTTP-egress controls). The C2 domain and Node built-in names (os, dns, process, resolve4) are stored as char-code arrays in lib/b02e30.js and lib/6ad264.js to defeat string-grep scanners. The package name bolt-delivery-menu-app impersonates the Bolt delivery brand while shipping generic 'Enterprise Utilities' boilerplate as its cover story, and the author email research@sl4x0.xyz resolves to the same domain as the exfil destination — the typosquat lure, the cover identity, and the C2 are one operation. README falsely claims 'No network requests'.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준