目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@ccfly/setup-darwin-x64

MAL-2026-12313
2026-08-06 14:21:51
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @ccfly/setup-darwin-x64 (npm)

凭据/密钥窃取
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
1,497
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@ccfly/setup-darwin-x640.1.0
npm@ccfly/setup-darwin-x640.1.1
npm@ccfly/setup-darwin-x640.1.13
npm@ccfly/setup-darwin-x640.1.14
npm@ccfly/setup-darwin-x640.1.15
npm@ccfly/setup-darwin-x640.1.16
npm@ccfly/setup-darwin-x640.1.3
npm@ccfly/setup-darwin-x640.1.6
npm@ccfly/setup-darwin-x640.1.7
npm@ccfly/setup-darwin-x640.1.8
npm@ccfly/setup-darwin-x640.1.9
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-12313","published":"2026-08-05T12:52:42Z","modified":"2026-08-06T14:21:50.709454965Z","summary":"Malicious code in @ccfly/setup-darwin-x64 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (409d11825a61bed068425296e83dcc0c87427579f7b5d724ec52e5e87465f2b5)\nThe package ships a prebuilt darwin/x64 Mach-O binary containing a Go agent (module github.com/ccfly/rescue) that, when executed, connects to a hardcoded remote broker at cc.hn / ccfly over WebSocket (ws://ccfly, wss://, https://cc.hn) using github.com/gorilla/websocket, spawns a pseudo-terminal via github.com/creack/pty, and pipes the WebSocket stream into that PTY. Symbols include agent.serve, agent.startPTY, agent.waitAuthorized, agent.wsBase and unixPTY.Read/Write/Resize/Close, giving the remote party interactive shell control of the host. A second stage (setup.downloadCcfly, setup.fetchAndExtract, setup.npmTarballURL, setup.extractFromTarGz, setup.runCcflyInstall, setup.redeemEnrollToken, setup.(*brokerClient).escalateToRescue, with a rodata reference to https://registry.npmjs.org) fetches and executes a further ccfly npm tarball after the broker approves an enrollment token — the additional code executed on the host is chosen by the remote broker, not the installer. The binary also inspects shell RC files and /etc/hosts (setup.scanShellProfilesForProxy, setup.checkProxyResidue, setup.checkHostsResidue, setup.runEnvChecks, setup.envReport) and POSTs an environment report back to the broker (setup.(*brokerClient).post; rodata latest.zshrc, export.ccfly).\n","affected":[{"package":{"name":"@ccfly/setup-darwin-x64","ecosystem":"npm"},"versions":["0.1.7","0.1.16","0.1.6","0.1.0","0.1.14","0.1.1","0.1.9","0.1.3","0.1.13","0.1.8","0.1.15"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bin/ccfly-setup","sha256":"689015ceb3abac6dd544c9ddcd3214a6d2eac9b60efd64847cf144c8c349f217","tlsh":"97664a03eca515a5c0add135cab6a253bf71bc890b2123d32b90f6283f77bd069b9754"}],"package_integrity":[{"filename":"setup-darwin-x64-0.1.7.tgz","hashes":{"sha1":"84df9e51a5e100f9d41600dbb5cfd6f22b071bc5","sha512_sri":"sha512-fzYVDkiLSGrZxsKfIXO+OMy12uOVfFZ7JZ+q9OkRvP7uQqe20IWqHhIKkT+xGxsjm4zgv846WWRw0373HEDFcg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.16"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.14"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.13"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ccfly/setup-darwin-x64/v/0.1.15"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014797","import_time":"2026-08-05T13:08:47.189036999Z","modified_time":"2026-08-05T12:52:42Z","sha256":"409d11825a61bed068425296e83dcc0c87427579f7b5d724ec52e5e87465f2b5","source":"amazon-inspector","versions":["0.1.7"]},{"id":"IN-MAL-2026-016519","import_time":"2026-08-06T14:19:53.419509046Z","modified_time":"2026-08-06T13:50:55Z","sha256":"7d21b399d2a5d722eb93d370a7b54a0fec6ecc05069feaa486ff27c4f1b67d40","source":"amazon-inspector","versions":["0.1.16"]},{"id":"IN-MAL-2026-016522","import_time":"2026-08-06T14:19:53.528820076Z","modified_time":"2026-08-06T13:51:19Z","sha256":"8e7e78a44b26b3fb9ef377c800143b3077591bc68fb213df369faa861db447dc","source":"amazon-inspector","versions":["0.1.6"]},{"id":"IN-MAL-2026-016520","import_time":"2026-08-06T14:19:53.450152568Z","modified_time":"2026-08-06T13:51:03Z","sha256":"a1c39be148994a61b85ef299e0681be4621cdf125a9bade628776c7a65d144ff","source":"amazon-inspector","versions":["0.1.0"]},{"id":"IN-MAL-2026-016521","import_time":"2026-08-06T14:19:53.494434323Z","modified_time":"2026-08-06T13:51:10Z","sha256":"f739222cb80305438dcdf3637dc6f07068b92bbd6ffc64a641dc651c50280359","source":"amazon-inspector","versions":["0.1.14"]},{"id":"IN-MAL-2026-016518","import_time":"2026-08-06T14:19:53.368940243Z","modified_time":"2026-08-06T13:50:47Z","sha256":"2d55cbc45ac2afe713585d7ec0d1463c8de7c7ccb854e7c793a1af1df71f1639","source":"amazon-inspector","versions":["0.1.1"]},{"id":"IN-MAL-2026-016523","import_time":"2026-08-06T14:19:53.570823163Z","modified_time":"2026-08-06T13:51:29Z","sha256":"8ffbb6d97a57594312533c9c836dd7a9f449c48313af350c1c8d7ab2d1a56cdb","source":"amazon-inspector","versions":["0.1.9"]},{"id":"IN-MAL-2026-016514","import_time":"2026-08-06T14:19:53.160726747Z","modified_time":"2026-08-06T13:50:16Z","sha256":"fc3777096264b562b86f3662bc29f2c09d3759397092fde394a7ec8fd5c58e05","source":"amazon-inspector","versions":["0.1.3"]},{"id":"IN-MAL-2026-016516","import_time":"2026-08-06T14:19:53.274234678Z","modified_time":"2026-08-06T13:50:31Z","sha256":"026b2da90a2fdf5903decd1bf5ec8329778b1c8d683ecdbb38cd17abc8e92df8","source":"amazon-inspector","versions":["0.1.13"]},{"id":"IN-MAL-2026-016515","import_time":"2026-08-06T14:19:53.240941455Z","modified_time":"2026-08-06T13:50:23Z","sha256":"273db652a085f38fc059d78e57a2591e784edbe0d89059885fb104e86dd2cb0c","source":"amazon-inspector","versions":["0.1.8"]},{"id":"IN-MAL-2026-016517","import_time":"2026-08-06T14:19:53.323963416Z","modified_time":"2026-08-06T13:50:40Z","sha256":"291482d6f72ebdb79abdbc258f737e01bafdae4ab79d0db2fb5116b44a6eab41","source":"amazon-inspector","versions":["0.1.15"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0