SECURITY ALERT: Malicious obfuscated code found in nextjs template #6400
Unanswered
peterkyle01
asked this question in
General
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
@syrusakbary I'm reporting an active supply-chain compromise in the Wasmer Next.js starter. The preinstall.js hook contains an obfuscated dropper using Unicode variation selectors to bypass static analysis.
It dynamically fetches encrypted logic from the Solana blockchain (Address: BjVeAjPrSKFiingBn4vZvghsGj9KCE8AJVtbc9S8o8SC). Even though the script crashed in my environment due to a property destructuring error, the intent to exfiltrate .env and .ssh data is clear. Recommend immediate removal of the repository.
Beta Was this translation helpful? Give feedback.
All reactions