An example package for training oneself that uses bin confusion to run a script
A counterfeit npm executable collects environment data and SSH-host information, then transmits it. It activates whenever the package-provided npm command is invoked.
Package declares a bin command that shadows a Node package-manager runtime executable.
package.jsonView on unpkgThe package registers an executable named npm, which points to npm.js.
package.jsonView on unpkg · L4The executable collects HOME and SECRET environment variables.
npm.jsView on unpkg · L9It reads part of the user's SSH known-hosts file and sends collected data in a request to a local HTTP endpoint.
npm.jsView on unpkg · L17The credential-collection function runs before the executable proxies arguments to npm.
npm.jsView on unpkg · L61This report applies to @selfpentest/bin-confusion@1.0.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The package registers an executable named npm, which points to npm.js.
package.jsonView on unpkg · L4Package declares a bin command that shadows a Node package-manager runtime executable.
package.jsonView on unpkgThe executable collects HOME and SECRET environment variables.
npm.jsView on unpkg · L9It reads part of the user's SSH known-hosts file and sends collected data in a request to a local HTTP endpoint.
npm.jsView on unpkg · L17The credential-collection function runs before the executable proxies arguments to npm.
npm.jsView on unpkg · L61