VDB
EN

MAL-2026-12669

Malicious code in dbk-ui-forms (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (36c6972ca0999559f2a4548843790c8000451acb4869da3c83d0357a655586ba) On `npm install`, the package's preinstall hook runs index.js which collects host identity (hostname, username, homedir, network interfaces, uid), output of `whoami`/`id`/`pwd`/`uname -a`, and the names of process.env variables matching a broad credential regex (key/token/secret/pass/auth/cred/npm/ci/build/jenkins/github/gitlab/aws/azure). The collected JSON is transmitted to the hardcoded Interactsh subdomain `ycwyyoimdcluajepubah2mvmkibt4h5wm.oast.fun` via HTTPS POST, HTTP POST, and DNS-encoded lookups. The package name and version (99.0.1) are consistent with a dependency-confusion beacon targeting internal build systems that resolve an unclaimed name from the public registry.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / dbk-ui-forms

No fixed version published yet for dbk-ui-forms (npm). Pin to a known-safe version or switch to an alternative.

참고