Supply-chain threat intelligence

Incident detail

criticalnpm·credential theft·osv

Malicious code in node-app-doctor (npm)

node-app-doctor

Risk score

92

AI summary

Indexed incident for node-app-doctor (npm).

Description

collect.js gathers host identifiers via os.hostname() and os.homedir(), reads local filesystem state with fs.existsSync, spawns child_process commands, and POSTs the collected data to the hardcoded endpoint http://aab.sportsontheweb.net. The destination domain is unrelated to any legitimate npm/Node tooling publisher and there is no plausible benign reason for a 'node app doctor' utility to ship installer/host telemetry to that host. The combination of system enumeration (hostname, home directory, child_process), filesystem inspection, and hardcoded plaintext HTTP POST to an unaffiliated domain is the standard host-fingerprint exfiltration shape.

Technical details

Affected versions

=1.0.9=1.0.2=1.0.1

Indicators

  • affected version=1.0.975%
  • affected version=1.0.275%
  • affected version=1.0.175%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents