Malicious code in intl-ads (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the package's scripts.preinstall runs poc.js which collects hostname, username, full network configuration (ipconfig/ip a/resolv.conf), id/whoami /all, git remote, parent package.json, and CI configuration files (.gitlab-ci.yml,.github/workflows, Jenkinsfile, azure-pipelines.yml). It then iterates process.env and harvests any variable whose name contains AWS, AZURE, GITHUB, GITLAB, JENKINS, NPM, TOKEN, CI, BUILD, etc. — capturing values, not just names — and POSTs the JSON payload to d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me over HTTPS, with a DNS callback as a secondary channel. The package self-describes as authorized bug-bounty research targeting Walmart's private namespace via dependency confusion, but the public npm registry has no scope restriction: any developer or CI system that resolves this name will execute the recon and leak credentials. The OAST destination is an Interactsh collector, not a Walmart-owned endpoint, so harvested data leaves any authorized scope. Concrete installer harm: AWS/Azure/GitHub/GitLab/npm tokens present in CI environment are exfiltrated; host fingerprinting enables follow-on attacks.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준