MAL-2026-12057
Malicious code in @zzzgenesis00/playwrite (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (28a7a4b265a274814769439b7bcc3e03e573308ac72036558815feabfec0c8af) The package @zzzgenesis00/playwrite is a typosquat of playwright. Its exported launch() returns empty stub methods, while postinstall.js (also loaded transitively via index.js) runs on npm install and require. It collects hostname, username, homedir, platform, cwd, node version, npm registry configuration and the output of `npm whoami` via execSync, and harvests credential-shaped environment variables including NPM_TOKEN, GITHUB_TOKEN, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, DOCKER_PASSWORD, GCLOUD_ACCESS_TOKEN and NPM_CONFIG. It enumerates ~/.ssh (id_rsa, id_ed25519, id_ecdsa and.pub files), reads ~/.npmrc and ~/.gitconfig, and scans Chrome, Chromium and Firefox profile directories for Cookies and Login Data. The collected data is JSON-POSTed over HTTPS to the hardcoded Serveo reverse-tunnel host 40f955f39128bd79-178-249-214-24.serveousercontent.com at path /collect, with a 2-second setTimeout delay and a try/catch wrapper commented to keep npm install silent on failure.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for @zzzgenesis00/playwrite (npm). Pin to a known-safe version or switch to an alternative.