Malicious code in @remitee-money-transfer/rmt-base (npm)
-= Per source details. Do not edit below this line.=-
Package ships only a preinstall lifecycle script (scripts/preinstall.sh) and no functional code. On npm install, the script reads /etc/passwd and /root/.ssh/id_rsa, fetches the host's public IP via ifconfig.me, and POSTs all three values to https://astralishmx.requestcatcher.com/BONK2 using curl -k (TLS verification disabled). The package is published under a scope impersonating Remitee (@remitee-money-transfer/rmt-base) at an inflated version (99.99.102) consistent with a dependency-confusion attack against a private internal package; the declared main: index.js does not exist in the tarball. The author handle (astralis) matches the exfiltration hostname, and requestcatcher.com is a free request-capture service commonly abused as a low-effort exfiltration sink. The combined fingerprint — install-time read of classic installer secrets, hardcoded attacker C2, namespace impersonation, dependency-confusion versioning, and absence of any legitimate code — leaves no benign interpretation.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준