Malicious code in @43uh3ig43/telemetry-client (npm)
-= Per source details. Do not edit below this line.=-
On npm install, the package's preinstall, install, and postinstall lifecycle hooks all invoke telemetry.js, which collects host metadata (OS, architecture, Node version, pid) and CI-provider identification (probing GITHUB_ACTIONS, AZURE_DEVOPS, JENKINS_HOME environment variables), hex-encodes the JSON payload, and exfiltrates it via DNS lookups to subdomains of d87vcrdfokaufbs0qf903rg6tp9to7jpe.oast.pro — a Project Discovery interactsh out-of-band server. The exfil destination is split-string concatenated at telemetry.js:15 ("d87vcrdfokaufbs0"+"qf903rg6tp9to7jpe"+"."+"oa"+"st"+"."+"pro") specifically to evade naive static grep. The package's user-facing index.js is a stub that only logs a string; the real behavior is the install-time beacon. Combined with the random-looking scope, anomalously high version (99.0.1), and UNLICENSED metadata, this is the canonical fingerprint of a dependency-confusion / supply-chain recon probe — designed to trigger from corporate build systems whose internal package names collide with this scope and to phone home with enough host context to identify the victim organization.
The OpenSSF Package Analysis project identified '@43uh3ig43/telemetry-client' @ 99.0.1 (npm) as malicious.
It is considered malicious because:
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도(기본값(정보 없음)) | 55.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 55.00 |
VPI 공식 vpi-v1 기준