MAL-2026-12812
Malicious code in ts-toolkit-plus (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (49d47be3f5dc16ea70755e0233f46106d3f50d1d5384a4f20c76b91463c9876c) The package's main entry defines a getPlugin() function that performs an HTTPS request to a hardcoded bare-IP endpoint at 31.97.137.157:45000/icons/112 and passes the response field data.credits to `new Function('require','module',...,'Promise', data.credits)`, executing whatever the remote host returns with full Node.js context including require, process, Buffer, and globalThis. The destination URL is assembled from split protocol/separator/domain/path fragments and wrapped in benign 'icon/CDN' naming that hides the code-execution sink. The declared dependencies (@primno/dpapi for Windows DPAPI unwrap of browser-stored secrets, node-machine-id for host fingerprinting, better-sqlite3/sqlite3 for browser profile databases, socket.io-client) do not correspond to the advertised 'crypto checkout' purpose and pre-stage tooling a remote payload can invoke via the injected require() to harvest Windows browser credentials and cookies. Any consumer that require/imports this package and reaches the getPlugin path grants the remote operator arbitrary code execution on the installer's machine.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for ts-toolkit-plus (npm). Pin to a known-safe version or switch to an alternative.