MAL-2026-13453
Malicious code in pilgrimage-portal-client (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (73b9f604c074795de9d79071f9e8a6c131e0a30159f6ea2a0769ded3df6d5a28) On `npm install`, the package's postinstall hook runs `node ping.js`, which reads the installer's hostname via `require('os').hostname()` and POSTs it, along with a timestamp and the package name/version, to the hardcoded bare-IP endpoint http://134.119.222.10:9009/canary over plain HTTP. Errors and timeouts are silently swallowed. The version number (99.0.0) and beacon shape are consistent with a dependency-confusion proof-of-install callback: the destination is a non-first-party bare IP the installer never configured, and the outbound call fires automatically without user consent. Regardless of the 'canary' self-label, host-identifier data leaves the installer's machine to an attacker-controlled endpoint at install time.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for pilgrimage-portal-client (npm). Pin to a known-safe version or switch to an alternative.