Weaknesses of type CWE-506

101 results

Código malicioso embutido

É quando código malicioso ou prejudicial é intencionalmente inserido em um software legítimo, seja por um desenvolvedor comprometido, uma dependência infectada ou um processo de build comprometido. O risco é que a aplicação executa ações maliciosas (roubo de dados, backdoor, espionagem) sem que o usuário ou mesmo a organização responsável saiba.

Example

Um desenvolvedor adiciona silenciosamente um trecho que envia credenciais de usuários para um servidor externo, ou uma biblioteca open-source popular é comprometida e passa a incluir código que minera criptomoredas nos servidores das empresas que a usam.

How to mitigate

Implementar revisão de código rigorosa e segregação de acesso (principle of least privilege), auditar dependências e versões de bibliotecas, usar integridade de artefatos (assinatura de pacotes, SBOM), e monitorar comportamento anômalo em execução (logs, atividade de rede). Também: manter cadeia de custódia clara do código-fonte e pipeline de build seguro.

CVE-2017-16069nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16054`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16072nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16060babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16202The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installatEPSS 1.2%CVE-2017-16049`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16064node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16068ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16074crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16065openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16075http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16070nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16046`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16204The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.EPSS 1.1%CVE-2017-16076proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16058gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16053`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16063node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16071nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16067node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%