MAL-2026-14119
Malicious code in bcc-design-icons (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2) bcc-design-icons@9999.0.0 declares a postinstall script `node./notify.js` that runs automatically on `npm install`. The script performs an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc with query parameters containing `os.hostname()` and the package name. The 9999.0.0 version, absence of any icon-library functionality expected from the package name, and callback-to-bare-IP shape match a dependency-confusion attack that identifies internal/private installers to the operator. Hostname is host-identifying data exfiltrated to an attacker-controlled destination without any installer opt-in.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for bcc-design-icons (npm). Pin to a known-safe version or switch to an alternative.