Malicious code in npmkekw (npm)
-= Per source details. Do not edit below this line.=-
The package's main module (index.js) exports an init() function that spawns /bin/bash via child_process.exec and opens a TCP socket to the hardcoded remote address 49.13.148.41:443, piping the shell's stdio through the socket — a textbook reverse-shell backdoor giving the operator at that IP interactive command execution on any host that calls init(). Package metadata is consistent with a throwaway attack vehicle: empty description, empty author, non-descriptive name npmkekw, and no other functional code. The payload as shipped contains a typo (references an undefined sh variable and pipes from cp.stdout) so it crashes on first use, but the intent and structure are unambiguous and a one-character fix would make it functional.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준