VDB
EN

MAL-2026-14029

Malicious code in axios-fast (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9cc76e819084a35126e067bd65bd3cf2fc52b6d8e068b67d14360ef71505fa7e) axios-fast@1.0.1 declares a preinstall lifecycle script in package.json that runs a Node one-liner which POSTs the entire process.env of the installing machine to a hardcoded webhook.site inbox (https://webhook.site/31e82bcd-a220-42e6-82f0-4f082e8fa80e/). The script fires automatically on npm install, before any code is reviewed, and dumps all environment variables — routinely including AWS_*, NPM_TOKEN, GH_TOKEN, and other CI/build secrets — to a third-party attacker-controlled endpoint. The package name typosquats the popular axios HTTP client but its shipped functionality is limited to this install-time exfiltration.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / axios-fast

No fixed version published yet for axios-fast (npm). Pin to a known-safe version or switch to an alternative.

참고