MAL-2026-12416
Malicious code in poly-custom-api (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a3263a9e2a986068fafa530a8e6862f9ba41cad05ecbd5b7b91752ca1c5af0c6) The default export getPlugin in index.js constructs an HTTPS URL from split constants pointing at the bare IP 46.183.25.232:45000/icons/108, fetches the response, and passes the response field data.credits to new Function(...) with require, module, exports, process, Buffer, and global injected as parameters. Any caller invoking the exported function grants the remote endpoint arbitrary code execution in the Node.js process with full host privileges. The endpoint is disguised with icon/CDN vocabulary (iconDomain, font-awesome/svgs/brands, a 'bearrtoken' field literal 'logo') and an unused IconProvider map, while the package advertises itself as a 'custom API library' — the icon framing is cover for the fetch-and-eval path. The payload is mutable, unpinned, unauthenticated, and served over a bare-IP host unrelated to any legitimate publisher infrastructure.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for poly-custom-api (npm). Pin to a known-safe version or switch to an alternative.