MAL-2026-13434
Malicious code in @lyxa.ai/core (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1a32d4762c92b12ad7fd0567dfa0f07470a01884303acdc7a3585bfb4ad7fff2) The exported bootstrapCore() unconditionally initializes the event bus with a hardcoded amqps:// URL containing embedded credentials for the author's CloudAMQP broker at dog.lmq.cloudamqp.com/vgyuplrd, with no override parameter. All events an installer publishes via publishEvent() flow through this author-owned exchange, and subscribeToEvent registers channel.consume handlers that JSON-parse incoming AMQP messages and invoke installer-registered subscriber methods as instance[methodName](payload) — meaning any party in possession of the shipped broker credentials can push messages that trigger arbitrary decorator-registered handlers in the installer's process with attacker-chosen payloads. ConfigurationService defaults redisURL to a hardcoded Redis Cloud endpoint (redis-12296.fcrce173.eu-west-1-1.ec2.redns.redis-cloud.com:12296) with embedded credentials, and SecretManagerService instantiates a GCP SecretManagerServiceClient using a shipped service-account private key for project for-poc-325210 to fetch MONGO_URL, which mongoose.connect() then uses — so installer cache state, secret lookups, and DB reads/writes default to author-controlled cloud accounts the installer never configured. The compiled bundle additionally ships a live GCP service-account private key (lyxa-core@for-poc-325210.iam.gserviceaccount.com), three Firebase Admin private keys (projects for-poc-325210, lyxa-rider-88939, lyxa-shop), a Redis Cloud password, and the CloudAMQP credentials, giving any third party administrative access to the same author-owned backends that installers of this package transitively depend on.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for @lyxa.ai/core (npm). Pin to a known-safe version or switch to an alternative.
참고
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.145-debug [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.144-test [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.16 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.8-debug-1 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.1.36 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.1.47 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.201 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.2.24 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.206 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.386 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.23 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.2.43 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.56 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.281 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.13 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.333 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.79 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.37 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.129 [PACKAGE]
- https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.162-test [PACKAGE]