Malicious code in faceplate-docs (npm)
MAL-2024-2355
Published · Modified
Dependency scanning
Check whether faceplate-docs is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (f5198954164869432a0fda9f3f723c1db53531ab2f73db84523e6f62946cf420)
faceplate-docs@99.9.10 runs index.js from a postinstall hook that collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. The beacon fires automatically on npm install without any user interaction. The package name plus implausibly high version (99.9.10) and the recon-only payload are characteristic of a dependency-confusion probe designed to identify internal build environments that mistakenly resolve a private package name from the public registry.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes