베타 Shoulder는 베타 버전입니다 — 결과가 가끔 잘못될 수 있습니다. 여러분의 피드백이 다음에 무엇을 고칠지 결정합니다. 피드백 공유

보안 알림

Shoulder의 에코시스템 분석 신호 — 스캔된 새 패키지, 감지된 위험 변경, 발견된 취약점.

Shoulder가 패키지를 분석하고 검토할 가치가 있는 신호를 감지하면 알림이 생성됩니다. 각 알림은 전체 위협 브리핑에 연결됩니다.

npm/@0dai-dev/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Install hook sends traffic to flagged target (raw IP / paste site / tunnel) — dropper
  • Install hook writes to system paths (/etc/, /usr/, etc.) — review for persistence
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + credential reads + network to suspicious target (raw IP / paste site / tunnel) — credential stealer; not a legitimate cloud SDK
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
npm/@chozzz/[email protected] CRITICAL

Bulk env-var sweep + shell exec at runtime — credential-stealer

  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
npm/@integrity-labs/[email protected] CRITICAL

Obfuscated payload + credential-harvest capability: javascript-obfuscator-grade output combined with cloud-metadata / bulk-env-sweep / cloud / SSH / browser / wallet credential access

  • matched: verdict_obfuscated_credential_exfil, verdict_runtime_payload_delivery
npm/@kong-ui-public/[email protected] MEDIUM

Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals

  • Dynamic code evaluation with network access — potential code injection or exfiltration
npm/@phenx-inc/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
  • Sensitive file access with network egress — credential exfiltration pattern
  • Install hook writes to user-home dotfiles (~/.bashrc, ~/.ssh/, ~/.local/bin/) — auto-installing persistence
npm/@podman-desktop/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
npm/@proxai/[email protected] CRITICAL

Install-time suspicious download: evidence contains raw IP, tunnel service, or paste site URL

  • matched: verdict_suspicious_install_download_source, verdict_runtime_payload_delivery
npm/@shopify/[email protected] MEDIUM

Cloud SDK import + env access + outbound network — capability acquisition + exercise

  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Sensitive file access with network egress — credential exfiltration pattern
vscode/[email protected] MEDIUM

Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)

npm/[email protected] MEDIUM

A dist-tag (e.g. latest) was moved to this version while it was less than 1 hour old — publish-side compromise indicator

  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
pypi/[email protected] MEDIUM

Cloud SDK import + env access + outbound network — capability acquisition + exercise

npm/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Bulk env-var sweep + shell exec at runtime — credential-stealer
  • Bulk env-var sweep (cap-bulk-env-access reads ALL of process.env) + outbound network — credential-stealer
  • Install hook spawns dynamic / forked-detached shell — dropper attribution
  • Install hook sends traffic to flagged target (raw IP / paste site / tunnel) — dropper
  • Raw socket usage paired with credential reads — possible TCP exfil bypass
  • Install hook writes to system paths (/etc/, /usr/, etc.) — review for persistence
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + credential reads + network to suspicious target (raw IP / paste site / tunnel) — credential stealer; not a legitimate cloud SDK
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)
  • Install hook + credential-file reads + network — credential stealer shape (scopes may be install or runtime; install hook can transitively reach runtime caps)
  • Sensitive file access with network egress — credential exfiltration pattern
  • Install hook writes to user-home dotfiles (~/.bashrc, ~/.ssh/, ~/.local/bin/) — auto-installing persistence
npm/[email protected] CRITICAL

Payload delivery from suspicious source: IOC URL + execution capability

  • Install hook sends traffic to flagged target (raw IP / paste site / tunnel) — dropper
  • Manifest repository URL points at a popular package's repo but this package's name differs — impersonation
  • Install hook writes to system paths (/etc/, /usr/, etc.) — review for persistence
  • Manifest version doesn't match any embedded version constant in the bundle — bundle may not have been rebuilt from the published manifest; review release pipeline and corroborating signals
  • Install hook + shell exec + network — dropper shape (scopes may be install or runtime; install hook can transitively reach runtime caps via the postinstall entrypoint)