VDB
EN

MAL-2026-13453

Malicious code in pilgrimage-portal-client (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (73b9f604c074795de9d79071f9e8a6c131e0a30159f6ea2a0769ded3df6d5a28) On `npm install`, the package's postinstall hook runs `node ping.js`, which reads the installer's hostname via `require('os').hostname()` and POSTs it, along with a timestamp and the package name/version, to the hardcoded bare-IP endpoint http://134.119.222.10:9009/canary over plain HTTP. Errors and timeouts are silently swallowed. The version number (99.0.0) and beacon shape are consistent with a dependency-confusion proof-of-install callback: the destination is a non-first-party bare IP the installer never configured, and the outbound call fires automatically without user consent. Regardless of the 'canary' self-label, host-identifier data leaves the installer's machine to an attacker-controlled endpoint at install time.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / pilgrimage-portal-client

No fixed version published yet for pilgrimage-portal-client (npm). Pin to a known-safe version or switch to an alternative.

참고