目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@lizhao1/memorax-code-internal

MAL-2026-12320
2026-08-06 14:21:51
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @lizhao1/memorax-code-internal (npm)

凭据/密钥窃取安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
407
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@lizhao1/memorax-code-internal0.1.0
npm@lizhao1/memorax-code-internal0.1.1
npm@lizhao1/memorax-code-internal0.1.2
npm@lizhao1/memorax-code-internal0.1.3
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-12320","published":"2026-08-05T12:25:58Z","modified":"2026-08-06T14:21:50.882836934Z","summary":"Malicious code in @lizhao1/memorax-code-internal (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b983c7d55b41a0eb0cd384b7efbdf186926e3e6ce1f88c62c8cf59a96e648285)\nThe npm postinstall script (bin/memorax-code-plugin-postinstall.mjs) unconditionally calls enableInternalDataCollectionConfig() with no user prompt, writing internal.data_collection.enabled=true and a self-defined consent string into ~/.memorax-code/config.toml, then starts a backend that harvests and transmits Codex and Claude Code session content. The backend module lib/memorax-code-backend/dist/internal-trace-collection-config.js hardcodes the destination http://47.112.192.211:8789/memorax-code/trace-collection (bare IP, plain HTTP, Alibaba Cloud netblock — not matching the advertised publisher domain code.memorax.net). flushInternalTraceCollection reads per-session events.jsonl and native rollout files for the configured AI clients and POSTs them in batches to that endpoint. Only a narrow allow-list of key names (authorization/api_key/secret/password) is redacted; user prompts, assistant replies, tool arguments, and file contents embedded in session events are transmitted in full. The 'consent' gate is satisfied by the postinstall itself writing the accepted consent-version string, and the pipeline is labeled 'internal data collection' / 'anonymous' despite shipping full session bodies to a hardcoded third-party endpoint.\n","affected":[{"package":{"name":"@lizhao1/memorax-code-internal","ecosystem":"npm"},"versions":["0.1.0","0.1.1","0.1.2","0.1.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bin/memorax-code-plugin-postinstall.mjs","sha256":"34b55ed5796ccceede42fde845dbfa6094327d5336703db230d5706361fe222d","tlsh":"e533c80878ef79320673506da41b8422b97c5d07210de970b7be465c6f8e16d83bfb6a"},{"path":"lib/memorax-code-backend/dist/internal-trace-collection-config.js","sha256":"63de3189a47db13680a8b03bc67f19288b42a4318f51fdc6536414926e21c839","tlsh":"05b1f41e7ce73e220a52b8dc854bc1566db86a43101c94e5f96c52c43fda57881f3bed"}],"package_integrity":[{"filename":"memorax-code-internal-0.1.0.tgz","hashes":{"sha1":"831369abce9e9f61c0679999d44de0000767b0aa","sha512_sri":"sha512-9xd7H9AQ16vavitTjAwxB311N7empwJu7TWJty0ZfRAPYBansEMqGVAtLfn9uJLO75E43hKBvfpr76YSxEOt/A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lizhao1/memorax-code-internal/v/0.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lizhao1/memorax-code-internal/v/0.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lizhao1/memorax-code-internal/v/0.1.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lizhao1/memorax-code-internal/v/0.1.3"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014653","import_time":"2026-08-05T13:08:34.137349047Z","modified_time":"2026-08-05T12:25:58Z","sha256":"b983c7d55b41a0eb0cd384b7efbdf186926e3e6ce1f88c62c8cf59a96e648285","source":"amazon-inspector","versions":["0.1.0"]},{"id":"IN-MAL-2026-014850","import_time":"2026-08-05T13:08:50.990545492Z","modified_time":"2026-08-05T13:01:15Z","sha256":"f4ae94e1d2cc2af7b2aa649bf10616ede12b1f25fef43a5afbc2eeb1675b1675","source":"amazon-inspector","versions":["0.1.1"]},{"id":"IN-MAL-2026-015840","import_time":"2026-08-05T19:04:53.760494706Z","modified_time":"2026-08-05T18:07:28Z","sha256":"05e39356232421d8cc201ffbe09dad80142de0a1966d278e5be5895ec492304f","source":"amazon-inspector","versions":["0.1.2"]},{"id":"IN-MAL-2026-016368","import_time":"2026-08-06T14:19:45.504262603Z","modified_time":"2026-08-06T13:14:25Z","sha256":"20a03f25c81165c853122032814ee9d7425900686323d31ccea6279c51fe2633","source":"amazon-inspector","versions":["0.1.3"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0