VDB
EN

MAL-2026-12435

Malicious code in sc-geeksquad-core (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2fd2458d8a5843f57187868a2c244a376dd3d2daef420d3c564c775ef6a2782a) sc-geeksquad-core@9999.0.0 declares a preinstall script `node callback.js` that runs automatically on `npm install`. The script collects the installer's hostname (`os.hostname()`), OS username (`os.userInfo().username`), current working directory (`process.cwd()`), configured npm registry (`npm_config_registry`), and a set of CI repository-slug environment variables (GITHUB_REPOSITORY, CI_PROJECT_PATH, BUILD_REPOSITORY_NAME, BITBUCKET_REPO_FULL_NAME, TRAVIS_REPO_SLUG, DRONE_REPO, BUILDKITE_PIPELINE_SLUG, CIRCLE_PROJECT_REPONAME, JOB_NAME), then sends them via HTTP GET to the hardcoded bare-IP endpoint `http://75.119.137.232:31337/depconfuse` as query parameters. The placeholder version `9999.0.0` combined with a generic scoped-sounding name is the canonical dependency-confusion reconnaissance shape: the package is published to public npm to intercept internal-package name resolution and beacon back which private-namespace builds are vulnerable to substitution.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / sc-geeksquad-core

No fixed version published yet for sc-geeksquad-core (npm). Pin to a known-safe version or switch to an alternative.

참고