MAL-2026-11071Malicious code in whs4_eud (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
1.0.0 | unavailable | — | — | — |
1.0.1 | archived | — | — | VIP 下载 |
| Ecosystem | Package | Version |
|---|---|---|
| npm | whs4_eud | 1.0.0 |
| npm | whs4_eud | 1.0.1 |
{"schema_version":"1.7.4","id":"MAL-2026-11071","published":"2026-07-25T15:55:34Z","modified":"2026-08-11T17:53:48.856319952Z","summary":"Malicious code in whs4_eud (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6be47b29c887fd54b5cffc8789278f3ea7987b12d618e89c540e5670edea12b5)\nwhs4_eud@1.0.1 declares a postinstall lifecycle script (`node index.js`) that fires unconditionally on `npm install`. On execution, index.js POSTs installer-side host information — the absolute path of the install location (which embeds the user's home directory), Node.js version, and platform/architecture — to a hardcoded Discord webhook under discord.com/api/webhooks/1530599209269465319/. The webhook URL is assembled by concatenating two string literals at runtime rather than appearing as a single literal, a light obfuscation of the exfiltration destination. The package name and layout are consistent with a dependency-confusion / typosquat beacon whose only functional behavior is to notify the author when an install occurs and to disclose where.\n\n## Source: ossf-package-analysis (d906ecaf9f2ede0a31c6966b9d8402f4c80e57fb72eae7f9dfa1b3a7c583b8d4)\nThe OpenSSF Package Analysis project identified 'whs4_eud' @ 1.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","affected":[{"package":{"name":"whs4_eud","ecosystem":"npm"},"versions":["1.0.1","1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"5cc9cd2e5a872d5b641b6a1c4bf5e201468b693e6eb9cc4053e4f9296ab52f20","tlsh":"0761518a96f022210ba3f3d4204bc12bbb2985132a0ecd45f64c47b41fce67dd4e52e8"}],"package_integrity":[{"filename":"whs4_eud-1.0.1.tgz","hashes":{"sha1":"8553c23b13668bdb44198b8b0fc6d836b7856c5f","sha512_sri":"sha512-m+Ga9ZEpPNwJbjyxLQtk2xzdtNrNPoyPw+cZSa8jXd8qPr46mD5UIg9pQFq9rRZfSdwEcPA28mmvB1/ZJ1lk/w=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/whs4_eud/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/whs4_eud/v/1.0.0"}],"database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-27T01:42:44.1209829Z","modified_time":"2026-07-25T15:55:34Z","sha256":"d906ecaf9f2ede0a31c6966b9d8402f4c80e57fb72eae7f9dfa1b3a7c583b8d4","source":"ossf-package-analysis","versions":["1.0.1"]},{"id":"IN-MAL-2026-011261","import_time":"2026-08-04T22:30:07.961552055Z","modified_time":"2026-08-04T21:55:43Z","sha256":"6be47b29c887fd54b5cffc8789278f3ea7987b12d618e89c540e5670edea12b5","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017376","import_time":"2026-08-11T17:51:59.251904999Z","modified_time":"2026-08-11T17:24:19Z","sha256":"f8dcbecbaf2392f7cd7720244800fde67c971fa7fa34fb8cf21d61c580dd4713","source":"amazon-inspector","versions":["1.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0