Malicious code in gifuct (npm)
-= Per source details. Do not edit below this line.=-
Package name typosquats the legitimate gifuct-js GIF parser and re-exports it as cover. On module load, code reconstructs the host filament-zap.vercel.app and paths /service/assets/fetchBinary / /service/assets/fetchLinuxBinary from String.fromCharCode numeric arrays, downloads a platform-specific executable, writes it to a WinMetrics/WinService.exe path under the user data directory, chmods it 0755 on Linux, and spawns it detached with stdio ignored and unref'd. The payload is fetched over an obfuscated, unpinned URL with no hash or signature verification, and the download-and-execute path is unrelated to the advertised GIF-parsing purpose.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준