目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

sysb1

MAL-2026-10428
2026-08-19 02:59:18
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in sysb1 (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
380
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0unavailable
1.0.1unavailable
1.0.2unavailable
1.0.4unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmsysb11.0.0
npmsysb11.0.1
npmsysb11.0.2
npmsysb11.0.3
npmsysb11.0.4
npmsysb11.0.5
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-10428","published":"2026-07-13T08:10:57Z","modified":"2026-08-19T02:59:18.396334203Z","summary":"Malicious code in sysb1 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4)\nThe npm package sysb1 advertises itself as a 'System binary configuration tool' but ships a Windows surveillance agent. index.js (declared as both main and bin) runs at load/start and silently installs the CPython 3.12 runtime via winget, falling back to downloading python-3.12.3-amd64.exe from python.org into the temp directory and running it with /quiet InstallAllUsers=0 PrependPath=1, then silently pip-installs surveillance libraries (keyboard, pyautogui, mss, uiautomation, pyperclip). It then spawns wscript.exe on start_tool.vbs detached and hidden; start_tool.vbs uses ShellExecute with the 'runas' verb and window state 0 to launch 'python pointer.py' as Administrator with no visible window. pointer.py captures clipboard content (pyperclip.paste), screenshots (ImageGrab, mss), and UI/accessibility text (uiautomation), and POSTs the collected data via requests.Session to a hardcoded endpoint https://iq-overlay-pointer.vercel.app/api that the installer did not configure. pointer.py also registers global keyboard hotkey hooks (keyboard.add_hotkey) that drive clipboard reads, screen OCR, keystroke injection (pyautogui.press), and network POSTs, running inside hidden overrideredirect/transparent-color Tk windows with a 'panic_exit' hotkey. Package metadata and identifiers ('IQPointer', 'ULTRA GHOST MODE', 'HACK 1/HACK 2', empty window titles) contradict the stated purpose and are a cover story.\n","affected":[{"package":{"name":"sysb1","ecosystem":"npm"},"versions":["1.0.0","1.0.2","1.0.1","1.0.4","1.0.5","1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"pointer.py","sha256":"a095aa6a4b08da23c6f2267bc18fe5f47342a3fa3225309796f54e1935f43207","tlsh":"4af22e09ec1d089ac073cd2f5952a853ff1a07439a5eda17f8bc99901f743468ae4ef9"},{"path":"index.js","sha256":"6044ff1e5d1929c7e31b6e77a4c000ae9400229fbd5733821f88fd2bad8f4cea","tlsh":"de8150075a95a234ed7247a99b07212be517a073b100e69cbcbe83840f76945c073fee"},{"path":"package.json","sha256":"139c49539ac589af5ba968636afa7ab26d48e8329bd119f40f96e3c8dc025731","tlsh":"7ce04f3399615c9344b58aa29a368a05b5718b3f00254c0f31bb511c97a29a245bbb5c"}],"package_integrity":[{"filename":"sysb1-1.0.0.tgz","hashes":{"sha1":"b4f01fdae03300e650abc68fb08988f6dc79d6ed","sha512_sri":"sha512-1CCAnieozV/7MSJ8BwTTmNK2hPScUQa9rDzqdamzfdgJSQFvaOoxeI/9Y1I/Wqm+kDzKhE6i/ZYus4d2Jf4tew=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sysb1/v/1.0.3"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-009863","import_time":"2026-07-13T09:10:56.016202745Z","modified_time":"2026-07-13T08:10:57Z","sha256":"95e8cd8412bd88621ce6b01197ff69e0dc347d017175fcbfe378cdc036407e27","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-010950","import_time":"2026-07-28T14:20:00.972282697Z","modified_time":"2026-07-28T13:40:44Z","sha256":"11f3fe2845ee2a07bcb82ebc43e8e28bdc4e35a96eee4bc2a82ac96c680807ea","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-010942","import_time":"2026-07-28T14:20:00.299051627Z","modified_time":"2026-07-28T13:39:41Z","sha256":"c8f32dffecdfce99c809df1dcd7d18d75cdab188d294e4b67c901e4916e89966","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017645","import_time":"2026-08-13T17:24:45.807833456Z","modified_time":"2026-08-13T17:17:15Z","sha256":"530efe2fec0ffeabda93aa5e9718161f131bb28d35f28432d5d2c2da6e4763a4","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-018305","import_time":"2026-08-19T02:57:22.605974205Z","modified_time":"2026-08-19T02:50:27Z","sha256":"6a81e81943d977a2c824a28ebbf6b78be0d78656f0dae96367f175d7fca5856b","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-018310","import_time":"2026-08-19T02:57:23.07809155Z","modified_time":"2026-08-19T02:51:09Z","sha256":"9b98909d13a2ac5f3f00667317f85fc354009d43538a10bc0f9023bc443b17a6","source":"amazon-inspector","versions":["1.0.3"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0