VDB
EN

MAL-2026-14445

Malicious code in digitalexp-style-module-l9 (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4c1b3e9059995d4d535c65fafd0105eea420510acb17ad9befbc99c18aa25df9) package.json declares both preinstall and postinstall as `node beacon.js`, so beacon.js runs automatically on every `npm install`. beacon.js reads os.hostname(), os.userInfo().username, process.cwd(), and the package name, hex-encodes the collected string, splits it into <=60-char DNS labels, and issues a DNS lookup against those labels under the author-controlled domain b0.rs. It additionally issues an HTTPS GET to https://b0.rs/?poc=...&host=...&cwd=... carrying the same fields in the query string. A source comment identifies the DNS-tunnel channel as chosen for its 'best chance of escaping egress-filtered CI', confirming the dual-channel design is intentional evasion. The version number 99.0.0 is consistent with a dependency-confusion payload targeting internal-scope name resolution.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / digitalexp-style-module-l9

No fixed version published yet for digitalexp-style-module-l9 (npm). Pin to a known-safe version or switch to an alternative.

참고