VDB
EN

MAL-2026-12803

Malicious code in shiftmarkets-sdk (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b1628a8b4e8b6c4c117f2a38f7d69664950c1d5758772c64c2225f296f681c29) The package declares a postinstall hook that runs dist/recon.js on npm install. The script collects hostname, username, sudo_user, homedir, cwd, internal IPv4 addresses of all network interfaces, DNS domain, CI indicators, and the full list of process.env variable names — including a subset filtered against a regex matching AWS/GCP/AZURE/NPM/TOKEN/SECRET/KEY/PASS/CRED/GITHUB/SSH keywords — and POSTs the JSON payload over plain HTTP to http://138.68.108.20/cb, a hardcoded bare IP unrelated to the package's stated SDK purpose. A docstring header labels the collection as 'NON-SENSITIVE telemetry only' while the code simultaneously enumerates and filters environment variable names for credential-shaped keywords, indicating deliberate mislabeling of pre-attack reconnaissance as benign telemetry.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / shiftmarkets-sdk

No fixed version published yet for shiftmarkets-sdk (npm). Pin to a known-safe version or switch to an alternative.

참고