stripe-internal-utils@1.0.0
Full RCE PoC -osama
→ 의심 전송지로 발송: wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
// System reconnaissance
패턴: reads-homedir
Packages whose static analysis matched this pattern. See the per-package detail pages for the offending code excerpt.
11개 패키지에 이 패턴이 매칭됨 (총 publish 이벤트 15건을 publisher+name 기준으로 묶음). 최신순.
Full RCE PoC -osama
→ 의심 전송지로 발송: wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
xxx
→ 의심 전송지로 발송: tjalcgvzuaojvayjfdfh1rtb4ojaobofs.oast.fun.
Full RCE PoC - Alex Birsan Style
→ 의심 전송지로 발송: wvmjioytxqdcokzvflqjv6v35ug1nfyjl.oast.fun.
CI/CD Security Posture Scanner — scores AWS, Terraform, CloudFormation, GitHub Actions, GitLab CI, Azure DevOps, Bitbucket Pipelines, Jenkins, CircleCI, Google Cloud Build, Buildkite, Drone CI, Tekton, Argo Workflows, Dockerfile, Kubernetes manifests, Helm charts, OCI image manifests, SCM repo posture (GitHub / GitLab / Bitbucket), npm and pypi dependency files against OWASP Top 10 CI/CD Risks and 14 other compliance frameworks
→ Worm self-propagation: package reads .npmrc _authToken AND invokes npm publish in install-path code. Shai-Hulud-class shape — no legitimate package re-publishes OTHER packages from the user's machine.
MCP server for environment security auditing. Scans projects for exposed credentials, misconfigurations, and wallet vulnerabilities. Recommended by the Web3 security community. Part of the DeFi Security Alliance toolchain.
→ 의심 전송지로 발송: webhook.site.
Openclaw 中文版 - WhatsApp gateway CLI (Baileys web) with Pi RPC agent
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s), 1 other host(s).
The official CLI for OpenClaw-CN Agent ecosystem
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 other host(s).
CLI tool to lint your markdown file for Chinese.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Yet another JS code coverage tool that computes statement, line, function and branch coverage with module loader hooks to transparently add coverage when running tests. Supports all JS coverage use cases including unit tests, server side functional tests
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).
Select a one-, two-dimensional or irregular region using the mouse.
→ 의심 전송지 없음, 원격 실행 형태 없음 — 1 known-vendor host(s).