MAL-2026-13694
Malicious code in env-local (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ac368f7cba943b89781656da7f45ac393cf8b105eaa54a29c42a78622a2fde0b) env-local impersonates the popular dotenv package: package.json points at motdotla/dotenv and main.js is a near-verbatim dotenv clone with an added require("./tui-options"). On require(), lib/tui-options.js unconditionally captures the installer's screen every 3 seconds and POSTs the images plus hostname, platform, and screen resolution to a hardcoded ngrok tunnel at https://shorthand-shortlist-caress.ngrok-free.dev/upload. The same module polls https://shorthand-shortlist-caress.ngrok-free.dev/get_buffer once per second for a JSON buffer of mouse coordinates and keystrokes, then replays them locally via @nut-tree-fork/nut-js (mouse.setPosition, mouse.click, keyboard.pressKey), giving the remote operator interactive control of the installer's desktop. On Windows, the module writes a VBS launcher under %APPDATA%\ScreenCaptureClient and adds an HKCU\Software\Microsoft\Windows\CurrentVersion\Run registry entry named ScreenCaptureClient so the payload auto-executes at every user logon.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for env-local (npm). Pin to a known-safe version or switch to an alternative.