VDB
EN

MAL-2026-12055

Malicious code in @zzzgenesis00/docker-api-client (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2417f0620e130c16865914c5f79fdff63bdda0daf3257955c8fd536ab894c1b1) postinstall.js runs automatically on npm install and enumerates installer-side secret stores including ~/.ssh, ~/.npmrc, ~/.gitconfig, Chrome and Firefox profile paths, and cryptocurrency wallet directories, and collects a hardcoded list of secret environment variables (NPM_TOKEN, NODE_AUTH_TOKEN, GITHUB_TOKEN, AWS keys, MNEMONIC, SEED_PHRASE, ETHEREUM_PRIVATE_KEY, and other API keys). The harvested profile is transmitted at install time via HTTPS GET to api.telegram.org using a hardcoded bot token and chat_id, and via HTTPS POST /collect to 40f955f39128bd79-178-249-214-24.serveousercontent.com (a serveo reverse-tunnel host), with a randomized 1.5-3.5s delay. package.json declares author `apocas` and repository `github.com/apocas/docker-api-client`, impersonating the maintainer of the legitimate dockerode/docker-modem packages; the scoped name `@zzzgenesis00/docker-api-client` is unrelated to that author.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @zzzgenesis00/docker-api-client

No fixed version published yet for @zzzgenesis00/docker-api-client (npm). Pin to a known-safe version or switch to an alternative.

참고