Fallos del tipo CWE-506

101 resultados

Código malicioso incorporado

É quando código malicioso é deliberadamente inserido dentro de um software legítimo durante o desenvolvimento, compilação ou distribuição. O atacante consegue executar ações não autorizadas (roubo de dados, backdoors, sabotagem) porque o código malicioso está embutido no binário confiável.

Ejemplo

Um desenvolvedor com acesso ao repositório insere silenciosamente código que envia credenciais de usuários para um servidor externo; ou um fornecedor de biblioteca terceira injeta um keylogger que ativa após a instalação. A vítima só descobre quando o dano já está feito.

Cómo mitigar

Implemente: (1) revisão de código rigorosa e assinatura digital de commits; (2) análise estática e dinâmica automática (SAST/DAST) no pipeline CI/CD; (3) verificação de integridade e autenticidade de dependências e pacotes; (4) auditoria de acessos a repositórios e build systems; (5) sandboxing e princípio de menor privilégio em produção.

CVE-2017-16059mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16058gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16203The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installaEPSS 1.1%CVE-2017-16067node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16050`sqlite.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16055`sqlserver` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16071nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16066opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16056mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16045`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16078shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16057nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16205The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installatEPSS 1.1%CVE-2017-16061tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16062node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2023-2003CRITICALEmbedded malicious code vulnerability in Unitronics Vision1210EPSS 0.9%CVE-2025-32965CRITICALCompromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2EPSS 0.9%CVE-2026-46412CRITICALMalicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud wormEPSS 0.8%CVE-2017-16207discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.EPSS 0.7%CVE-2017-20203CRITICALNetSarang v5.0 Malicious Backdoor Supply Chain CompromiseEPSS 0.7%