VDB
EN

MAL-2026-13448

Malicious code in lib-frontsga (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (53a65c44cfdcbc89df47508f3f87fcab836f1fa2f4adf2298ecfb47cd6088038) Package name 'lib-frontsga' published to the public npm registry at version 9.999.999 targets an internal package name via dependency-confusion resolution. A preinstall/postinstall lifecycle script (poc.js) runs on npm install and collects host identifiers (hostname, username, cwd, Node version) together with CI/build attribution (GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, GITHUB_ACTOR, GITHUB_RUN_ID, GITHUB_WORKFLOW, npm_config_registry, RUNNER_NAME, AWS_REGION, and Azure/Jenkins/GitLab identifiers). The collected data is transmitted to a hardcoded Interactsh callback subdomain via DNS queries and HTTP/HTTPS POST to votspfykpbaortacnitltze3m5k5swzg6.oast.fun. Any organization that internally uses this name without a scoped/internal registry pin will resolve this public copy and execute the install-time beacon, disclosing internal build-environment fingerprints to a third-party out-of-band server.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / lib-frontsga

No fixed version published yet for lib-frontsga (npm). Pin to a known-safe version or switch to an alternative.

참고