THREATPKG
SYNC STALE

Supply-chain threat intelligence

Incident detail

criticalnpm·credential theft·osv

Malicious code in pc-optimizer (npm)

pc-optimizer

Risk score

92

AI summary

Indexed incident for pc-optimizer (npm).

Description

The package's collect.js imports child_process, fs, http, https, and os, reads host identifiers via os.hostname() and os.homedir(), inspects local filesystem paths via fs.existsSync, and POSTs collected data to a hardcoded external endpoint at http://aab.sportsontheweb.net. The destination is not a registry, vendor SDK host, or documented service — it is an unrelated third-party domain bound to a POST in install/load-reachable code. The combination of system enumeration (hostname, homedir, child_process), filesystem inspection, and a hardcoded non-publisher exfiltration endpoint is the canonical host-information stealer fingerprint and provides direct attacker benefit (host fingerprinting + arbitrary collected data shipped off-host).

Technical details

Affected versions

=1.0.1=1.0.2=1.0.9

Indicators

  • affected version=1.0.175%
  • affected version=1.0.275%
  • affected version=1.0.975%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents