logo

Database

Use of software with malware In vitest-cli-pro

Description

Package published as vitest-cli-pro ships a verbatim copy of nodemailer as cover; its declared postinstall runs lib/utils/index.js, which detaches a child Node process to execute lib/utils/smtp-connection/index.js. That file performs an HTTPS GET to https://api.jsonbin.io/v3/b/6a62bc86da38895dfe879659 and passes the returned record.cookie value to new Function(require) for immediate execution. The JSON bin is attacker-controlled and mutable, so arbitrary JavaScript runs on any machine executing npm install vitest-cli-pro, under the installer's user account. The nodemailer main and the vitest-branded name serve as a cover story for the dropper.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version