目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

hehehee

MAL-2026-10462
2026-08-19 09:17:17
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in hehehee (npm)

凭据/密钥窃取安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
495
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.9unavailable
2.0.19unavailable
2.0.21archivedVIP 下载
2.0.22unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmhehehee1.0.9
npmhehehee2.0.19
npmhehehee2.0.21
npmhehehee2.0.22
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-10462","published":"2026-07-13T17:48:34Z","modified":"2026-08-19T09:17:16.672093707Z","summary":"Malicious code in hehehee (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (efc5c7d437f7024811aab8bf68e70fb18366e843a3ee3048dc3dfe628bde5628)\nPackage metadata and README advertise a 'Windows diagnostic utility' / 'high-performance DOM utility', but the actual code (main.js) is a stealth Electron overlay designed to defeat Safe Exam Browser and similar proctoring tools. config.json ships a real-looking `__Secure-next-auth.session-token` JWE for chatgpt.com; main.js loads it at startup and injects it into a `persist:chatgpt` Electron session before navigating to chatgpt.com, so every screenshot/UIA-extracted text the tool sends through ChatGPT goes through a hardcoded account that the package author (or whoever harvested the cookie) controls and can read in conversation history. The bin (bin/kalamasha-tool.js) copies the bundled electron.exe to a sibling named `SearchFilterHost.exe` (the real Windows Search Filter Host system binary) inside node_modules/electron/dist and spawns it as a detached watchdog with randomised 1–25s respawn jitter, persisting under `%LOCALAPPDATA%\\Microsoft\\Windows\\Diagnostics` (a path mimicking a Microsoft-owned directory) and only stopping when a `.kill_watchdog` file appears. The CLI also auto-runs `npm install <missing> --no-save` at runtime for missing native modules without user consent. The combination of fraudulent package description, process-name masquerade as a Windows system binary, persistence with anti-kill respawn, anti-proctor stealth (WDA_EXCLUDEFROMCAPTURE, anti-Alt-Tab styling, cross-desktop migration), and a hardcoded ChatGPT session that silently relays user screen content to a third-party account constitutes a clear supply-chain harm to anyone following the README's quick-start instructions.\n","affected":[{"package":{"name":"hehehee","ecosystem":"npm"},"versions":["1.0.9","2.0.21","2.0.22","2.0.19"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"config.json","sha256":"324f44847850605042c9deb9ef43aaec2b836de0bec9643157d95d82624cd144","tlsh":"63916cc198766407501f60fee87b2689a21a1783f325e91e70a483070b7b2b79ca2574"},{"path":"main.js","sha256":"82d95719cb7a1522470d2978fa73f44ccedc35206e5cc11a1cc9a16ddc706edd","tlsh":"6b93e7596021213584326f768b37ad16f726a123e441d354beacc3d82fb1459ceb2fee"},{"path":"bin/kalamasha-tool.js","sha256":"426a20b401c6a1ab58b7014d3c89b4d5e7b011ef25307c482c29b02f782cfff0","tlsh":"d4f15249a266133459b15fea5b331c0adb2bd123d5455384b89c83ca3f3642ccda6eee"}],"package_integrity":[{"filename":"hehehee-2.0.21.tgz","hashes":{"sha1":"93df89d5093c7e397196d25adde7142d712a29d1","sha512_sri":"sha512-A39/nEJZaMc0Pm35GCb0PrkZ1ODKOi2FnZ4Y9qFLRMfP6fY9gzzbDPJSBYhzpPkxw3krKrko7Fg76RXyKga7uA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/hehehee/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/hehehee/v/2.0.21"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/hehehee/v/2.0.22"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/hehehee/v/2.0.19"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-010279","import_time":"2026-07-13T18:10:13.061629775Z","modified_time":"2026-07-13T17:48:34Z","sha256":"efc5c7d437f7024811aab8bf68e70fb18366e843a3ee3048dc3dfe628bde5628","source":"amazon-inspector","versions":["1.0.9"]},{"id":"IN-MAL-2026-015834","import_time":"2026-08-05T18:07:50.74852506Z","modified_time":"2026-08-05T17:26:26Z","sha256":"198ce12fe394dbca0c22ccbcce2586ce8ce3b7eb99f327fd08141096357d6399","source":"amazon-inspector","versions":["2.0.21"]},{"id":"IN-MAL-2026-015835","import_time":"2026-08-05T18:07:50.896388448Z","modified_time":"2026-08-05T17:26:37Z","sha256":"939a19607dacefc200d82c1e7798b2c83036579affc958f2a6083b5eaa3690a8","source":"amazon-inspector","versions":["2.0.22"]},{"id":"IN-MAL-2026-018414","import_time":"2026-08-19T09:15:25.056435452Z","modified_time":"2026-08-19T08:50:28Z","sha256":"28becc967fd781d77b0f8c2fd714ead0e013eec144ad2141dd7c2451a56f1ddd","source":"amazon-inspector","versions":["2.0.19"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0