VDB
EN

MAL-2026-13549

Malicious code in dojo-rn-interview (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (42dcf2c659fc0c8b63b90671ae2a865a7811d5eeaaf321aab8355358117be47d) dojo-rn-interview@1.0.1 declares a preinstall script that runs index.js on `npm install`. The script collects host identifiers via os.hostname(), os.userInfo(), os.homedir(), __dirname, and DNS server list, and reads the installer's /etc/passwd and /etc/hosts files, then POSTs the collected data over HTTPS to the hardcoded Burp Collaborator subdomain kqepxa9s4krgw7e7b6f7kufiy943stgi.oastify.com. The package name and behavior are consistent with a dependency-confusion reconnaissance beacon targeting internal build systems.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / dojo-rn-interview

No fixed version published yet for dojo-rn-interview (npm). Pin to a known-safe version or switch to an alternative.

참고