Falhas do tipo CWE-506

90 resultados

Código malicioso embutido

É quando código malicioso é intencionalmente inserido dentro de um componente legítimo de software, muitas vezes durante o desenvolvimento, build ou distribuição. O risco é que a aplicação executa lógica destrutiva ou de exfiltração de dados sem que o usuário final (ou até o proprietário) tenha consciência.

Exemplo

Um desenvolvedor comprometido adiciona uma função que envia credenciais de usuários para um servidor externo sempre que um formulário de login é submetido. O código fica dorminhoco na base de código e passa por code review se o revisor não estiver atento ou também estiver comprometido.

Como mitigar

Implemente verificação de integridade de código (assinatura digital de builds), auditoria rigorosa de mudanças via git history e acesso restrito ao repositório, testes de segurança automatizados que detectem chamadas suspeitas para servidores externos, e isolamento de ambientes de desenvolvimento e produção.

CVE-2017-16069nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16060babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16049`nodesqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16202The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installatEPSS 1.2%CVE-2017-16054`nodefabric` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16064node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16070nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16074crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16065openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16075http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.2%CVE-2017-16046`mariadb` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2025-59374CRITICAL"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced throEPSS 1.1%KEVCVE-2017-16079smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16073noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16059mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16076proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16053`fabric-js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16071nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%CVE-2017-16204The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.EPSS 1.1%CVE-2017-16063node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.EPSS 1.1%