VDB
EN

MAL-2026-4731

Malicious code in wml-core (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (46afe229d6efe1ef10d025302ed21e5c2c44bdd772c8fbb28d037cb1215c84ba) wml-core@99.0.1 is a dependency-confusion package targeting an internal `wml-*` namespace, published with an inflated version (99.0.1) to win npm resolution against an internal package of the same name. The `preinstall` script `poc.js` runs automatically on `npm install` and harvests: hostname, username, OS/platform info, full network configuration (`ipconfig /all` on Windows or `ip a` + `/etc/resolv.conf` on Linux), `whoami /all` / `id` output, git remote URLs, the parent project's `package.json`, CI configuration files (`.gitlab-ci.yml`, `.github/workflows/*`, `Jenkinsfile`, `azure-pipelines.yml`), and a filtered dump of `process.env` matching credential-bearing prefixes including `TOKEN`, `AWS`, `AZURE`, `NPM`, `GITHUB`, `GITLAB`, `JENKINS`, `WALMART`, `WMT`, `CI_`. The collected JSON blob is POSTed to `d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me` (an Interactsh out-of-band callback host) over HTTPS, with a DNS callback emitted as a side channel. Any installer outside the intended target scope — including unintended internal builds and any third party who installs this name — has their build environment, CI secrets, and cloud/registry tokens exfiltrated. The package's self-description as 'authorized bug bounty research' does not change installer-side harm: the payload fires unconditionally on any `npm install`.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / wml-core

No fixed version published yet for wml-core (npm). Pin to a known-safe version or switch to an alternative.

참고