VDB
EN

MAL-2026-12790

Malicious code in glia-functions-tools (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (e24f6c700225d22dcccdf1af7bb58c7628366ccc59b864431af5123909b42626) package.json's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, and current working directory, reads /etc/passwd and /etc/hosts, and HTTPS-POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain. The exfiltration fires automatically on npm install without any user interaction, and targets installer-side system identity and account data.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / glia-functions-tools

No fixed version published yet for glia-functions-tools (npm). Pin to a known-safe version or switch to an alternative.

참고