MAL-2026-13979
Malicious code in eslint-generate-prerelease (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (26b3f1a7acd55a1642c9615fe72871781a6c0d6bea6f9d31aa42c700aa799704) Package ships an empty module (index.js = 'module.exports = {};') under a name that resembles internal tooling, published at an inflated version 99.9.1 — the canonical shape used to win version resolution against a private-registry package of the same name. Its single dependency, 'ltidisafe', is declared not as a registry package but as a direct tarball URL on a Google Cloud Storage bucket (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.6.2.tgz). On `npm install`, npm fetches that tarball from a location the registry does not audit and executes any lifecycle scripts and main module it contains. The path segment 'depenconf' and the version-inflation pattern are consistent with a targeted dependency-confusion attack. The lure package itself is hollow; the harm arrives through the URL-pinned transitive dependency.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for eslint-generate-prerelease (npm). Pin to a known-safe version or switch to an alternative.