VDB
EN

MAL-2026-13966

Malicious code in tizen-webdriver-cli (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cf90f542c0f81ff50f903a216f44a5870bc0ac5ede472fa2c41af447994b58e4) On npm install, the package's postinstall lifecycle script collects host identifiers (os.hostname(), process.platform, process.arch, Node.js version, package name, and npm lifecycle event) and POSTs them as JSON over HTTPS to the hardcoded endpoint https://8kq1s58l.instances.poc.jchunt.top/tizen-webdriver-cli, with a 3-second timeout and errors silently swallowed. The behavior runs unconditionally at install time with no opt-in, no disclosure in normal install output, and no first-party relationship between the destination host and the package's advertised purpose (a Tizen WebDriver CLI, resembling shaka-project's generic-webdriver-server Tizen backend). The package name suggests dependency-confusion targeting of that legitimate project.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / tizen-webdriver-cli

No fixed version published yet for tizen-webdriver-cli (npm). Pin to a known-safe version or switch to an alternative.

참고