目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

tt-help-cli-ycl

MAL-2026-12488
2026-08-07 14:28:48
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in tt-help-cli-ycl (npm)

远程访问后门安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
3,623
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.4.57unavailable
1.4.58unavailable
1.4.59unavailable
1.4.60unavailable
1.4.61archivedVIP 下载
1.4.62unavailable
1.4.63unavailable
1.4.64unavailable
1.4.65unavailable
1.4.66unavailable
1.4.67unavailable
1.4.68unavailable
1.4.69unavailable
1.4.70unavailable
1.4.71unavailable
1.4.72unavailable
1.4.73unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmtt-help-cli-ycl1.4.57
npmtt-help-cli-ycl1.4.58
npmtt-help-cli-ycl1.4.59
npmtt-help-cli-ycl1.4.60
npmtt-help-cli-ycl1.4.61
npmtt-help-cli-ycl1.4.62
npmtt-help-cli-ycl1.4.63
npmtt-help-cli-ycl1.4.64
npmtt-help-cli-ycl1.4.65
npmtt-help-cli-ycl1.4.66
npmtt-help-cli-ycl1.4.67
npmtt-help-cli-ycl1.4.68
npmtt-help-cli-ycl1.4.69
npmtt-help-cli-ycl1.4.70
npmtt-help-cli-ycl1.4.71
npmtt-help-cli-ycl1.4.72
npmtt-help-cli-ycl1.4.73
npmtt-help-cli-ycl1.4.74
npmtt-help-cli-ycl1.4.75
npmtt-help-cli-ycl1.4.76
npmtt-help-cli-ycl1.4.78
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-12488","published":"2026-08-05T12:17:18Z","modified":"2026-08-07T14:28:47.956346856Z","summary":"Malicious code in tt-help-cli-ycl (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6)\nThe package's `tt-help watchdog` subcommand starts a long-running agent that POSTs heartbeats to a remote server (default hardcoded to http://117.71.53.99:17301, referenced in src/lib/constants.js and the README/run-explore examples) and executes commands returned in the response. In WatchdogAgent, syncCommands maps entries from the server's `commands` array into child_process.spawn(command, { shell: true }) via ProcessManager.startCommand, with auto-restart — the remote operator selects arbitrary shell commands to run on the installer's host. Each heartbeat body assembled by _buildHeartbeatBody carries hostname, non-internal IPv4 address, OS platform/release/arch, CPU count, memory, node version, uptime, load average, and the contents of ~/.tt-help.json (server, proxy, browser, userId, tuning fields), POSTed as JSON to ${serverUrl}/api/watchdog/heartbeat at the configured interval (default 15s). In addition, _startUpgradeChecker polls the npm registry every 10 minutes and, when a new version of tt-help-cli-ycl is published, invokes `npm install -g tt-help-cli-ycl@latest` via child_process.exec and re-spawns, so the publisher can push arbitrary new code to every running agent host without user confirmation. The combination of remote-command execution, ongoing host inventory + stored-config exfiltration to a bare-IP destination, and unattended auto-upgrade constitutes a full command-and-control backdoor rather than a legitimate remote-management tool.\n","affected":[{"package":{"name":"tt-help-cli-ycl","ecosystem":"npm"},"versions":["1.4.61","1.4.59","1.4.60","1.4.63","1.4.64","1.4.67","1.4.71","1.4.65","1.4.70","1.4.66","1.4.57","1.4.73","1.4.62","1.4.69","1.4.72","1.4.58","1.4.68","1.4.74","1.4.78","1.4.75","1.4.76"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/watchdog/process-manager.js","sha256":"2793e929cce7d05d3d13c28b85698fcc3db19cd79429ad40942284d6f9f3cc4b","tlsh":"a512b41958fd01577ab300141beba1162aa1a50faa09fe587dfd9b680fc847405f2be8"},{"path":"scripts/run-explore.sh","sha256":"8bb4d832911102a6ff59b54747a1f5786a77a0c3fbe8c1861395a9f6b93d1b8e","tlsh":"2e9175c37d4d8a309265cae26892212ef267425b19097dd4f0a1d12b3c5cfbaa73d5a3"},{"path":"src/watchdog/agent.js","sha256":"827b95a667158573376a44554fe8971deb96146d4774c68674af904490318ec3","tlsh":"70d193098aff00666876115a6f2700032971a20f1d87ed0cbfad47cd8fd9a3c85a5fb5"},{"path":"src/watchdog/upgrader.js","sha256":"33fab057b3a6c40a1029282d285543009874bb0dd68ec87a0f2e5bddf74c5447","tlsh":"515130c929f7613182b2b22da61f9015377681432b4eee11ba9d47106f4a824a5b3fcc"}],"package_integrity":[{"filename":"tt-help-cli-ycl-1.4.61.tgz","hashes":{"sha1":"b3c9e9704661f6175ab4449585c0500cfa69dc7e","sha512_sri":"sha512-s4cB/UfGLIS0T1uIfEZ7zcB0w3zqvMTxBX774HldzBaPU0mK+hP8pO6dIcGMbjLlF14ayUawiMvUAzx9t2eJug=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.61"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.59"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.60"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.63"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.64"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.67"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.71"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.65"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.70"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.66"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.57"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.73"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.62"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.69"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.72"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.58"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.68"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.74"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.78"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.75"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tt-help-cli-ycl/v/1.4.76"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014817","import_time":"2026-08-05T13:08:48.762843245Z","modified_time":"2026-08-05T12:56:32Z","sha256":"425b148abb84342912d6e2caf046da7ccf806a32c1b3950a3d41366980fd3eed","source":"amazon-inspector","versions":["1.4.61"]},{"id":"IN-MAL-2026-014793","import_time":"2026-08-05T13:08:46.902424357Z","modified_time":"2026-08-05T12:52:06Z","sha256":"5246f6fbb6e6d46a9a9cab000fb5e2c2f2816831f9df67f64803054c92423963","source":"amazon-inspector","versions":["1.4.59"]},{"id":"IN-MAL-2026-014633","import_time":"2026-08-05T13:08:32.162615831Z","modified_time":"2026-08-05T12:17:18Z","sha256":"dc827d9593cc7d3cb899922b4e5a26de6ae026ca1994165607b9fb63bcf71207","source":"amazon-inspector","versions":["1.4.60"]},{"id":"IN-MAL-2026-015793","import_time":"2026-08-05T16:13:45.719027921Z","modified_time":"2026-08-05T15:41:09Z","sha256":"2b08749c0630d26064b36e3071e5baea85518db047bbbba08354d016de4dc317","source":"amazon-inspector","versions":["1.4.63"]},{"id":"IN-MAL-2026-015790","import_time":"2026-08-05T16:13:45.498283711Z","modified_time":"2026-08-05T15:40:37Z","sha256":"e6144be61d70f258741e5d4cc1476021f93e3ce82ffa00a3f86189537a1438a6","source":"amazon-inspector","versions":["1.4.64"]},{"id":"IN-MAL-2026-016261","import_time":"2026-08-06T13:09:07.945422116Z","modified_time":"2026-08-06T12:55:14Z","sha256":"0dd6259fc4fef46022321a36e47e5fa376b3ea75efd865739972cefe81d39f44","source":"amazon-inspector","versions":["1.4.67"]},{"id":"IN-MAL-2026-016258","import_time":"2026-08-06T13:09:07.632603577Z","modified_time":"2026-08-06T12:54:47Z","sha256":"10e07f1b41f6d7006d567df95e1b0c8d66b0421acc475728775b7202b0100645","source":"amazon-inspector","versions":["1.4.71"]},{"id":"IN-MAL-2026-016255","import_time":"2026-08-06T13:09:07.368667765Z","modified_time":"2026-08-06T12:54:20Z","sha256":"37d7042d1599b8debfbd542ec7e3a1f863a2d0d8ae75776f34b43f0886e0f439","source":"amazon-inspector","versions":["1.4.65"]},{"id":"IN-MAL-2026-016256","import_time":"2026-08-06T13:09:07.458991897Z","modified_time":"2026-08-06T12:54:31Z","sha256":"402f9b1404d216c056fe64795e3b99247cfa3d2e622e639ea7d2e3353c1e2deb","source":"amazon-inspector","versions":["1.4.70"]},{"id":"IN-MAL-2026-016265","import_time":"2026-08-06T13:09:08.397459136Z","modified_time":"2026-08-06T12:55:49Z","sha256":"9847510afa4b965a2dcac10901f9904c43bcf5f2652e51b755ab18509cc20ad5","source":"amazon-inspector","versions":["1.4.66"]},{"id":"IN-MAL-2026-016266","import_time":"2026-08-06T13:09:08.540731744Z","modified_time":"2026-08-06T12:56:00Z","sha256":"be0b9d48edaef660b4d633e0211492e7b5a16c73a04fda03b4111e6975de4f4c","source":"amazon-inspector","versions":["1.4.57"]},{"id":"IN-MAL-2026-016257","import_time":"2026-08-06T13:09:07.54585318Z","modified_time":"2026-08-06T12:54:38Z","sha256":"e8582513a8f8461374843816fddae5c0e10e1bc9b8eec62751a5a93a37dcc598","source":"amazon-inspector","versions":["1.4.73"]},{"id":"IN-MAL-2026-016260","import_time":"2026-08-06T13:09:07.824506707Z","modified_time":"2026-08-06T12:55:04Z","sha256":"ec04b56635a7ef02a3e026f79a1ff0bd91f4b3208b2ebf34d35b66dacd2ad3b8","source":"amazon-inspector","versions":["1.4.62"]},{"id":"IN-MAL-2026-016262","import_time":"2026-08-06T13:09:08.032578342Z","modified_time":"2026-08-06T12:55:22Z","sha256":"a49b203a895b6dc9765e7bca1f48efdc4bd1f51e6ac1c5a85b3a3aefd274e093","source":"amazon-inspector","versions":["1.4.69"]},{"id":"IN-MAL-2026-016259","import_time":"2026-08-06T13:09:07.719135616Z","modified_time":"2026-08-06T12:54:55Z","sha256":"b1a2cabd93a9d96eecf5fd8356a9ef7ad867d758a00844d7852c7acd87871779","source":"amazon-inspector","versions":["1.4.72"]},{"id":"IN-MAL-2026-016263","import_time":"2026-08-06T13:09:08.183971467Z","modified_time":"2026-08-06T12:55:32Z","sha256":"ee3080a4ce6b88ee9bb8dac5c5881b9c3479b0cbf9aa31ad63cbc01c34ebcec4","source":"amazon-inspector","versions":["1.4.58"]},{"id":"IN-MAL-2026-016264","import_time":"2026-08-06T13:09:08.271523493Z","modified_time":"2026-08-06T12:55:39Z","sha256":"f7e11b8aa382aca577ceb5b4b96fb55e893903af9547b7394b21981723b50271","source":"amazon-inspector","versions":["1.4.68"]},{"id":"IN-MAL-2026-016364","import_time":"2026-08-06T14:19:45.341736184Z","modified_time":"2026-08-06T13:10:34Z","sha256":"a6a7892e662701e9afec65b057e5e62c0271ba4e9486fd93355d54940caaa77a","source":"amazon-inspector","versions":["1.4.74"]},{"id":"IN-MAL-2026-017079","import_time":"2026-08-07T14:26:54.308294612Z","modified_time":"2026-08-07T13:41:08Z","sha256":"53e5ac496bfe78550d62897473d919a91ca99b9d2094e3b047154a1b06b3ae24","source":"amazon-inspector","versions":["1.4.78"]},{"id":"IN-MAL-2026-017078","import_time":"2026-08-07T14:26:54.250984304Z","modified_time":"2026-08-07T13:41:00Z","sha256":"d48ae50449c449b787861aaa24f700d9d2e934dbf414b9d184f2af80b1bd2105","source":"amazon-inspector","versions":["1.4.75"]},{"id":"IN-MAL-2026-017080","import_time":"2026-08-07T14:26:54.371045548Z","modified_time":"2026-08-07T13:41:16Z","sha256":"0ebb6712b5224c449113cdc08e378e3bdde0d4fa85f4a88a712a8b0dacf34dc2","source":"amazon-inspector","versions":["1.4.76"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0