目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

app-soda-layer

MAL-2026-11128
2026-08-06 04:12:54
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in app-soda-layer (npm)

凭据/密钥窃取远程访问后门安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
130
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
2.1.6archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmapp-soda-layer2.1.6
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-11128","published":"2026-07-28T09:00:00Z","modified":"2026-08-06T04:12:53.502944819Z","summary":"Malicious code in app-soda-layer (npm)","details":"app-soda-layer 2.1.6 is an npm credential stealer and SSH backdoor that runs automatically on `npm install` through a `postinstall` hook (`test.js`). It harvests Solana keypairs (`id.json`), `config.toml` and `.env` secrets, then installs an operator-supplied SSH key into `~/.ssh/authorized_keys` and opens port 22 for persistent access. Any host that installed it should be treated as compromised: check `~/.ssh/authorized_keys` for the key below, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable `.env` files. The package was purpose-built rather than a compromised library: its name and only version were created 284 ms apart with no earlier release, published 2026-07-27T18:47:46Z and unpublished by the author about 2.5 hours later, so it now returns 404 and survives only in sandbox capture.\n\nThe payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new infrastructure. The exported function names, the `authorized_keys`/`chown -R`/`ufw allow 22/tcp` sequence, the `/api/ssh-key`, `/api/scan-patterns`, `/api/block-patterns` and `/api/v1` endpoints, and the file-target list all match, and the same toolkit was reported in #1366 (`polymarket-mcp-v2` 2.1.6, C2 170.205.31.203). One routine POSTs a hardcoded `id.json`/`config.toml`/`.env` harvest to the C2 prefixed with the OS username; a second fetches a live pattern list and recursively uploads matches from the home directory, or from every logical drive on Windows via `wmic`/PowerShell. The infrastructure rotates per deployment while the code does not, so the stable indicators are the endpoint names and the injected SSH public key, whose comment field impersonates the support address of an unrelated company and is omitted here (match the base64 body): `ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFYMx8MqdYTD/aZjqxmXo+9460+9EvsSjfiy9YAU+xwY`. The pattern list retrieved live on 2026-07-28 was `.env`, `.xls`, `.xlsx`, `privatekey`, `private key`, `seed`, `wallet`, `key`, `phrase`, `private` (case-insensitive substring).\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f0857a9d8b1484b56b0ba1c671f5077125b8c898012aa57b0dd8813694206f53)\nThe package's postinstall hook (test.js) executes multiple malicious payloads on npm install. It walks the current working directory for files matching id.json, config.toml,.env, and env, and POSTs each to http://95.216.118.146:3000/api/v1 prefixed with the OS username. A second routine fetches attacker-controlled scan and block patterns from http://95.216.118.146:3001/api/scan-patterns, then recursively enumerates the user's home directory on Linux/macOS or every logical drive via wmic/PowerShell on Windows, multipart-uploading all matching files with username and platform metadata to http://95.216.118.146:3001/api/v1. On Linux, addSshKeyToUser() retrieves an SSH public key from http://95.216.118.146:3001/api/ssh-key, appends it to $HOME/.ssh/authorized_keys, chowns ~/.ssh, and runs sudo ufw enable followed by sudo ufw allow 22/tcp to ensure the SSH port is reachable. Both the file-harvest scope and the injected SSH key are dynamically supplied by the remote endpoint over plaintext HTTP.\n","affected":[{"package":{"name":"app-soda-layer","ecosystem":"npm"},"versions":["2.1.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"816709b97cc4a1c5c0943813d804c3e8dee9e940bfa808bf4b86ddb10fcc523c","tlsh":"0b02624c96fb2a21c2b371ac465f1406b59ac0033949cd91b6cc93546f8f93d69f2e9e"}],"package_integrity":[{"filename":"app-soda-layer-2.1.6.tgz","hashes":{"sha1":"eddb0444a94aa8b5e678c4906cbac333658556f8","sha512_sri":"sha512-pevIbrCfrpAyun+xfHpeoc+tjvlIs+9NiOiFfz34xFzgV2bCgs0b4p9zCND3vI9s3UwqsI7WnflGMr27dKg1nw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/app-soda-layer/v/2.1.6"},{"type":"REPORT","url":"https://protet.io/disclosures/app-soda-layer-2.1.6"},{"type":"EVIDENCE","url":"https://protet.io/package-analysis/npm/app-soda-layer/2.1.6"},{"type":"ARTICLE","url":"https://www.stepsecurity.io/blog/malicious-polymarket-bot-hides-in-hijacked-dev-protocol-github-org-and-steals-wallet-keys"}],"database_specific":{"iocs":{"ips":["95.216.118.146"],"urls":["http://95.216.118.146:3000/api/v1","http://95.216.118.146:3001/api/v1","http://95.216.118.146:3001/api/ssh-key","http://95.216.118.146:3001/api/scan-patterns","http://95.216.118.146:3001/api/block-patterns"]},"malicious-packages-origins":[{"id":"IN-MAL-2026-010868","import_time":"2026-07-28T14:19:56.596768159Z","modified_time":"2026-07-28T13:29:26Z","sha256":"f0857a9d8b1484b56b0ba1c671f5077125b8c898012aa57b0dd8813694206f53","source":"amazon-inspector","versions":["2.1.6"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Robin Frehner, Protet","contact":["https://protet.io","mailto:hello@protet.io"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0