目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

ach-detail

MAL-2026-12334
2026-08-06 23:29:18
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in ach-detail (npm)

安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
320
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmach-detail99.0.1
npmach-detail99.0.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-12334","published":"2026-08-05T13:04:48Z","modified":"2026-08-06T23:29:17.817770892Z","summary":"Malicious code in ach-detail (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6c8ce91cbe1aaa587613795b1b82cc84384b499a29af4a18c0a820b77ea1d834)\nThe npm package ach-detail@99.0.1 ships a preinstall lifecycle script (scripts/preinstall.js) that runs automatically on `npm install`. The script collects the installer's hostname, package name and version, Node.js version, platform, timestamp, and a nonce, and POSTs the payload to a hardcoded remote endpoint at https://callback.kuldeep.io/beacon, with an HTTP fallback to the same host. The package is published to the public npm registry at version 99.0.1 — a version-inflation pattern consistent with dependency-confusion targeting of a private internal package of the same name. A log string in the script self-labels the behavior as an authorized bug-bounty PoC, but that label is author-controlled, does not change the observable behavior, and does not represent consent from any installer that resolves the package (accidentally or through dependency-confusion). Installer-side host identifiers leave the machine to a non-first-party endpoint on install.\n","affected":[{"package":{"name":"ach-detail","ecosystem":"npm"},"versions":["99.0.2","99.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/preinstall.js","sha256":"8c488575448939da69a7abb168d73970e44dfb49523ca530368269a487ab2e8b","tlsh":"4fb1fe9b6ce1b0742662e2f60b5f6158f37ae403005ed560bc4e83506f941ada37eafd"}],"package_integrity":[{"filename":"ach-detail-99.0.2.tgz","hashes":{"sha1":"cc07eaa6975085edc7f2c06d45a6166d86a2a9ca","sha512_sri":"sha512-eglA47hmMFu/25697LSmLaskzccQWS0ftp4gzx0upXGnbJpWPFh1BdyGcP4IpOsfVkFuVDTGg6L2501WnY3qWw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ach-detail/v/99.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ach-detail/v/99.0.1"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014873","import_time":"2026-08-05T13:08:52.297461707Z","modified_time":"2026-08-05T13:04:48Z","sha256":"136c9cd3535c5ebb047f79bd6de88016db816903f1623cf96b5e765c78cab97e","source":"amazon-inspector","versions":["99.0.2"]},{"id":"IN-MAL-2026-016674","import_time":"2026-08-06T18:09:04.343064017Z","modified_time":"2026-08-06T16:19:21Z","sha256":"6c8ce91cbe1aaa587613795b1b82cc84384b499a29af4a18c0a820b77ea1d834","source":"amazon-inspector","versions":["99.0.1"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0