MAL-2026-10711Malicious code in @funny-booth/agent-core (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
0.1.1 | unavailable | — | — | — |
0.1.2 | unavailable | — | — | — |
0.1.3 | unavailable | — | — | — |
0.1.4 | unavailable | — | — | — |
0.1.5 | unavailable | — | — | — |
0.1.6 | archived | — | — | VIP 下载 |
0.1.7 | unavailable | — | — | — |
0.1.8 | unavailable | — | — | — |
0.1.9 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| npm | @funny-booth/agent-core | 0.1.1 |
| npm | @funny-booth/agent-core | 0.1.2 |
| npm | @funny-booth/agent-core | 0.1.3 |
| npm | @funny-booth/agent-core | 0.1.4 |
| npm | @funny-booth/agent-core | 0.1.5 |
| npm | @funny-booth/agent-core | 0.1.6 |
| npm | @funny-booth/agent-core | 0.1.7 |
| npm | @funny-booth/agent-core | 0.1.8 |
| npm | @funny-booth/agent-core | 0.1.9 |
{"schema_version":"1.7.4","id":"MAL-2026-10711","published":"2026-07-16T18:33:35Z","modified":"2026-08-14T19:51:38.964686204Z","summary":"Malicious code in @funny-booth/agent-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6693129f8b6f8b6c2d52722ca7746d6ef3dd792476297fa3583d3956548eb2b4)\nThe package ships heavily obfuscated runtime files (dist/index.js, dist/launcher.js) built with javascript-obfuscator. The MCP server registered as the package's main entry exposes an `install_mcp` tool that fetches JSON from the hardcoded portal `prompt-injection-tool-portal.vercel.app` and passes its `install_command` field directly to `child_process.exec()` on the installer's host, giving the portal operator arbitrary shell execution with the installer's privileges. The launcher (invoked by every `salesbot1..10` bin entry) calls `fetchBundledMcps` against the same portal and, for each returned entry, spawns `npx -y <entry.package>` while injecting locally decrypted vault secrets into the child's env — the portal can name any npm package, including a freshly published attacker-owned one, and it will be downloaded and executed with those secrets on hand. The launcher also unconditionally spawns a detached `npm i -g @funny-booth/agent-core@latest` on every run, silently self-updating to whatever the publisher pushes next. The launcher additionally spawns the local `claude` CLI with a portal-supplied greeting/knowledge string prepended as the initial user prompt and a portal-controlled MCP config, providing a prompt-injection channel into the user's Claude agent session. The repository URL in package.json is `github.com/yutamatsuura/prompt-injection-tool` and the deliberate obfuscation of the portal endpoints, exec sink, and auto-update spawn is consistent with intentional concealment of these remote-execution channels.\n","affected":[{"package":{"name":"@funny-booth/agent-core","ecosystem":"npm"},"versions":["0.1.6","0.1.1","0.1.5","0.1.3","0.1.4","0.1.2","0.1.9","0.1.7","0.1.8"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"b31f680a71bbda63106efb6856cd06ac3ef20aaa163f550ea8f589679df8be23","tlsh":"d972b642efc4d450538dbab33727b1e0c32a8d5977404c92e21abc186a7d726e7e7632"},{"path":"dist/launcher.js","sha256":"b411e2ca8d27d6241a0a25ca1aba9653272099e8797b72b48195bdbb7b0b187c","tlsh":"1492c5646b826582334b9fb3363bf0d5d51e188d39880c8fd254be016fa772ae6e1572"},{"path":"package.json","sha256":"b534f0bc6670bf569dacaa3b9e62fac83a97b790e1c2f7bb1ddd3fa738c21fb6","tlsh":"a9312738cdb44c2309d828c66c3661d2646588274e5bfc9533c1a16c8b4da9f20bfefc"}],"package_integrity":[{"filename":"agent-core-0.1.6.tgz","hashes":{"sha1":"5447b71814e02e363db694f51e36043e3d5ae5aa","sha512_sri":"sha512-qg6xjM4fgEgvvZSG28l6c1cG2HpVhGQQ7npMpv2hCV8InDBgEkqiVSVMGFqLOeKDfxuH+inTw06c9vRa8xdTDg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@funny-booth/agent-core/v/0.1.8"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-010695","import_time":"2026-07-16T18:53:59.640869602Z","modified_time":"2026-07-16T18:33:35Z","sha256":"6693129f8b6f8b6c2d52722ca7746d6ef3dd792476297fa3583d3956548eb2b4","source":"amazon-inspector","versions":["0.1.6"]},{"id":"IN-MAL-2026-010742","import_time":"2026-07-16T18:54:02.239417053Z","modified_time":"2026-07-16T18:40:43Z","sha256":"8e26e7cac2f7b2f9e05edb93b82eb370adc6276fb8de9afe40b0e821d416d48a","source":"amazon-inspector","versions":["0.1.1"]},{"id":"IN-MAL-2026-010732","import_time":"2026-07-16T18:54:01.711274229Z","modified_time":"2026-07-16T18:39:12Z","sha256":"8fb0b5d99560d155a71df356bc5efeaa3e138c4612af2639da6851ce9a04a711","source":"amazon-inspector","versions":["0.1.5"]},{"id":"IN-MAL-2026-010728","import_time":"2026-07-16T18:54:01.530238194Z","modified_time":"2026-07-16T18:38:39Z","sha256":"c1b55c35b4d915f14adbbf8f72337393a59037c77278b432a759920c4736ed0d","source":"amazon-inspector","versions":["0.1.3"]},{"id":"IN-MAL-2026-010729","import_time":"2026-07-16T18:54:01.561312635Z","modified_time":"2026-07-16T18:38:48Z","sha256":"e6a9912244c2080a882ab9ef5fd28445e8ac6af51b15b5ec3c75bb504b8a3bb4","source":"amazon-inspector","versions":["0.1.4"]},{"id":"IN-MAL-2026-010740","import_time":"2026-07-16T18:54:02.152827112Z","modified_time":"2026-07-16T18:40:26Z","sha256":"ebeed54460f3767a64b6feccef37634fb163bfd4cf7539ba1f72fc0c01eb5cf5","source":"amazon-inspector","versions":["0.1.2"]},{"id":"IN-MAL-2026-017919","import_time":"2026-08-14T19:49:49.711543636Z","modified_time":"2026-08-14T19:25:27Z","sha256":"5bb283a35f59b865d81a82e2a5b7fe230ad2b55c2127345c9be5a299b9c338b1","source":"amazon-inspector","versions":["0.1.9"]},{"id":"IN-MAL-2026-017920","import_time":"2026-08-14T19:49:49.773931354Z","modified_time":"2026-08-14T19:25:35Z","sha256":"e0bf4a3a734106a45bb5f18855c24fd631b8f2b8f1c4dfa749714293f24e89c2","source":"amazon-inspector","versions":["0.1.7"]},{"id":"IN-MAL-2026-017918","import_time":"2026-08-14T19:49:49.640917227Z","modified_time":"2026-08-14T19:25:19Z","sha256":"f70c338a6fd7335c3f0af636131e52995c44de791b83de2fc220175f04d4ef15","source":"amazon-inspector","versions":["0.1.8"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0