Weaknesses of type CWE-506

90 results

Código malicioso embutido

É quando código malicioso ou prejudicial é intencionalmente inserido em um software legítimo, seja por um desenvolvedor comprometido, uma dependência infectada ou um processo de build comprometido. O risco é que a aplicação executa ações maliciosas (roubo de dados, backdoor, espionagem) sem que o usuário ou mesmo a organização responsável saiba.

Example

Um desenvolvedor adiciona silenciosamente um trecho que envia credenciais de usuários para um servidor externo, ou uma biblioteca open-source popular é comprometida e passa a incluir código que minera criptomoredas nos servidores das empresas que a usam.

How to mitigate

Implementar revisão de código rigorosa e segregação de acesso (principle of least privilege), auditar dependências e versões de bibliotecas, usar integridade de artefatos (assinatura de pacotes, SBOM), e monitorar comportamento anômalo em execução (logs, atividade de rede). Também: manter cadeia de custódia clara do código-fonte e pipeline de build seguro.

CVE-2024-3094CRITICALXz: malicious code in distributed sourceEPSS 86.0%CVE-2025-30066HIGHtj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were afEPSS 72.4%KEVCVE-2026-33634CRITICALTrivy ecosystem supply chain briefly compromisedEPSS 59.2%KEVCVE-2024-4978HIGHMalicious Code in Justice AV Solutions (JAVS) ViewerEPSS 26.9%KEVCVE-2025-54313HIGHeslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected pEPSS 4.1%KEVCVE-2026-45321CRITICALMalware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keysEPSS 2.3%KEVCVE-2025-30154HIGHMultiple Reviewdog actions were compromised during a specific time periodEPSS 2.3%KEVCVE-2026-48027CRITICALCompromised Nx Console version 18.95.0EPSS 1.8%KEVCVE-2017-16044`d3.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.5%CVE-2026-8398CRITICALA supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434)EPSS 1.5%KEVCVE-2017-16128The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.EPSS 1.5%CVE-2020-15165CRITICALPotentially tampered sources on Play Store for Chameleon Mini Live DebuggerEPSS 1.3%CVE-2017-16051`sqliter` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.3%CVE-2017-16081cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.3%CVE-2017-16047mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.3%CVE-2017-16077mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16052`node-fabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16048`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16054`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16049`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%