MAL-2026-14235
Malicious code in config-helper-kit (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1033a9895c7d1a1b4d2c3f671caa239bd40f3985ab71d096fd25fbb7c977ef71) config-helper-kit@1.3.2 exposes a default function getPlugin that issues an HTTPS request to a hardcoded bare-IP host (https://31.97.137.157:45000/icons/109) and passes the returned data.credits field into `new Function('require','module',...)`, executing attacker-controlled JavaScript in the caller's Node.js process with `require` and `module` injected. The file also ships an unused helper referencing legitimate CDN hostnames (cloudflare, fastly, akamai, cdnjs) and uses icon/logo/credits naming, while the actual network target is a bare IP unrelated to any CDN. The package's README advertises it as a TypeScript/Tailwind config helper; the remote-code-fetch-and-execute behavior is undocumented and unrelated to that purpose. Any consumer that imports and invokes the default export grants the operator of 31.97.137.157:45000 arbitrary code execution on the installer's host.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for config-helper-kit (npm). Pin to a known-safe version or switch to an alternative.