VDB
EN

MAL-2026-14175

Malicious code in core-js-gns (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ae5eadad92952db436b03dd9673b34d203d9296b0913389de2aa0d9fef441631) The package's postinstall hook (`package.json` → `node init.js`) runs an installer-side dropper. init.js gates on developer-machine heuristics (presence of Desktop/Documents/Downloads directories) and a 24-hour skip marker, then POSTs hostname, username, platform, architecture, Node version, OS release, and package name/version to https://core-js-buffer.domaup-com.workers.dev/report. It then HTTP GETs an AES-256-GCM ciphertext from the same host with TLS verification disabled (`rejectUnauthorized: false`), decrypts it with a key derived from a hardcoded seed, checks the plaintext contains the cover-story string `TelemetrySender`, writes the result to `~/.cache/core-js-buffer/modules/runtime.py`, and spawns Python detached (`stdio:'ignore'`, `.unref()`) to execute it. The package name mimics the legitimate `core-js` library. Behavior is arbitrary remote code execution on the installer's machine, fetched from an attacker-controlled endpoint at npm install time, preceded by installer identifier exfiltration to the same endpoint.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / core-js-gns

No fixed version published yet for core-js-gns (npm). Pin to a known-safe version or switch to an alternative.

참고