VDB
EN

MAL-2026-14234

Malicious code in commandor-lib (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (2e184348abf5c5ce61ee6c4e63189411a08755e57e95dac33c666adae7c6dc2d) The package's scripts/postinstall.js runs automatically on npm install and imports child_process alongside http.request with multiple POST call sites (lines 13, 95, 194). This pattern in a lifecycle hook — spawning subprocesses and posting data to an external HTTP endpoint at install time — is consistent with installer-side reconnaissance and exfiltration to an author-controlled destination and does not correspond to any documented purpose of a generically named library package.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / commandor-lib

No fixed version published yet for commandor-lib (npm). Pin to a known-safe version or switch to an alternative.

참고