Weaknesses of type CWE-506

101 results

Código malicioso embutido

É quando código malicioso ou prejudicial é intencionalmente inserido em um software legítimo, seja por um desenvolvedor comprometido, uma dependência infectada ou um processo de build comprometido. O risco é que a aplicação executa ações maliciosas (roubo de dados, backdoor, espionagem) sem que o usuário ou mesmo a organização responsável saiba.

Example

Um desenvolvedor adiciona silenciosamente um trecho que envia credenciais de usuários para um servidor externo, ou uma biblioteca open-source popular é comprometida e passa a incluir código que minera criptomoredas nos servidores das empresas que a usam.

How to mitigate

Implementar revisão de código rigorosa e segregação de acesso (principle of least privilege), auditar dependências e versões de bibliotecas, usar integridade de artefatos (assinatura de pacotes, SBOM), e monitorar comportamento anômalo em execução (logs, atividade de rede). Também: manter cadeia de custódia clara do código-fonte e pipeline de build seguro.

CVE-2017-16059mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16058gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16203The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installaEPSS 1.1%CVE-2017-16067node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16050`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16055`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16071nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16066opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16056mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16045`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16078shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16057nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16205The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installatEPSS 1.1%CVE-2017-16061tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16062node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2023-2003CRITICALEmbedded malicious code vulnerability in Unitronics Vision1210EPSS 0.9%CVE-2025-32965CRITICALCompromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2EPSS 0.9%CVE-2026-46412CRITICALMalicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud wormEPSS 0.8%CVE-2017-16207discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.EPSS 0.7%CVE-2017-20203CRITICALNetSarang v5.0 Malicious Backdoor Supply Chain CompromiseEPSS 0.7%