VDB
EN

MAL-2026-13968

Malicious code in @hzero-front-ui/cfg (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d280060b3d704c67c4a2cc853fde425220e6a3606f71269daa8a9b3e74052f6d) package.json declares preinstall and install lifecycle scripts that, on npm install, collect whoami, hostname, current working directory, and npm_package_name, base64-encode the concatenation, and transmit it to subdomains of callback.m0chan.co.uk via both an HTTPS GET (curl to https://<sub>.callback.m0chan.co.uk/<b64>) and a DNS lookup (nslookup against <pkgdns>.<sub>.callback.m0chan.co.uk). The 99.99.99 version and scoped name pattern are consistent with a dependency-confusion beacon targeting an internal @hzero-front-ui scope.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / @hzero-front-ui/cfg

No fixed version published yet for @hzero-front-ui/cfg (npm). Pin to a known-safe version or switch to an alternative.

참고