VDB
EN

MAL-2026-12815

Malicious code in widget-forge (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5dc77fe941595018023e8382eac28ffdf8d1b000217a0e4d01e56e7bb48ac2d8) widget-forge@9999.0.0 is a dependency-confusion beacon. package.json declares scripts.preinstall = 'node callback.js', which auto-runs on npm install. callback.js collects os.hostname(), os.userInfo().username, process.cwd(), npm_config_registry, and CI repository identifiers (GITHUB_REPOSITORY and related CI env vars) and sends them via HTTP GET to the hardcoded bare-IP endpoint http://75.119.137.232:31337/depconfuse?pkg=.... The package has no functional payload: main is an empty object export, the description is a generic placeholder, and the version 9999.0.0 is the pattern used to outbid internal package versions in dependency-confusion attacks. The only effect of installation is the recon callback to the hardcoded IP.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / widget-forge

No fixed version published yet for widget-forge (npm). Pin to a known-safe version or switch to an alternative.

참고