VDB
EN

MAL-2026-12033

Malicious code in aedes_clusters (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6f0750fab7cca2996255b57d6fa98107b2d6b710fc8ab62f30345158ff3b7560) The package's package.json declares a `preinstall: node index.js` hook that fires automatically on `npm install`. index.js collects host reconnaissance data (os.hostname(), os.userInfo().username, home directory, DNS server configuration) and reads local system files including /etc/passwd and /etc/hosts, then HTTPS-POSTs the collected data to the hardcoded Burp Collaborator subdomain b5hv16nakzo45px5ga4ukkum8de52vqk.oastify.com. oastify.com is Burp Suite's out-of-band interaction service, commonly used as an attacker-controlled exfiltration sink. There is no legitimate functionality; the package's sole install-time behavior is host recon and data exfiltration.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / aedes_clusters

No fixed version published yet for aedes_clusters (npm). Pin to a known-safe version or switch to an alternative.

참고