MAL-2026-14029
Malicious code in axios-fast (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9cc76e819084a35126e067bd65bd3cf2fc52b6d8e068b67d14360ef71505fa7e) axios-fast@1.0.1 declares a preinstall lifecycle script in package.json that runs a Node one-liner which POSTs the entire process.env of the installing machine to a hardcoded webhook.site inbox (https://webhook.site/31e82bcd-a220-42e6-82f0-4f082e8fa80e/). The script fires automatically on npm install, before any code is reviewed, and dumps all environment variables — routinely including AWS_*, NPM_TOKEN, GH_TOKEN, and other CI/build secrets — to a third-party attacker-controlled endpoint. The package name typosquats the popular axios HTTP client but its shipped functionality is limited to this install-time exfiltration.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for axios-fast (npm). Pin to a known-safe version or switch to an alternative.