目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

app-kst-engine

MAL-2026-13358
2026-08-05 17:22:35
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in app-kst-engine (npm)

凭据/密钥窃取安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmapp-kst-engine2.1.6
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-05T17:22:35Z","published":"2026-08-05T17:22:35Z","schema_version":"1.7.4","id":"MAL-2026-13358","summary":"Malicious code in app-kst-engine (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (08cfc426d2f4b29bba2b81f2eb56eeee32ab114338a51fae5eeced2571e6b2d9)\nOn npm install, package.json's postinstall runs `node test.js`, which triggers three malicious paths against the installer. (1) A recursive scan of the current working directory collects files matching id.json, config.toml, Config.toml, env, and.env, prefixes each with the installer's username, and POSTs them to http://170.205.31.203:3000/api/v1. (2) Scan patterns are fetched from http://170.205.31.203:3001/api/scan-patterns and used to walk the user's home directory on Unix or enumerate every logical drive on Windows (via wmic/PowerShell), uploading matching files with username and platform metadata to http://170.205.31.203:3001/api/v1. (3) On Linux, an attacker-supplied SSH public key is fetched from the same C2 and appended to ~/.ssh/authorized_keys with mode 0o600, then `sudo ufw allow 22/tcp` is invoked to open the firewall, granting persistent remote SSH access. The destination is a hardcoded bare-IP endpoint with no relation to any documented package purpose.\n","affected":[{"package":{"ecosystem":"npm","name":"app-kst-engine"},"versions":["2.1.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"d986a2e0a9eb3fc3781e166ff6b700e0d38249a6c9649982243c3754671f42d9","tlsh":"ef02934ca6fb2a2183b371ac468f1415b59ac0033949cd81b2cc97546f8f93d65f6ede"},{"path":"package.json","sha256":"8296bee9db2ba7b59b3078e94f24e8a38f4a61d7f631e390180c3c2553709ff9","tlsh":"b9f0ed27ca588e6318f176a868bc0617f681932f4100880f35bd274c4fb61330089f1e"}],"package_integrity":[{"filename":"app-kst-engine-2.1.6.tgz","hashes":{"sha1":"306b98eaa8833598d7ad27bebfb2e40bb543e692","sha512_sri":"sha512-m63B/uKfUcmCNsvj1RWr5FcZui+XLwtWEydPH5ojn3S0yqKmJnn+xEDK5Pzt1zOjnumilSfsKT0I8Mvk1MLYzg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/app-kst-engine/v/2.1.6"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015831","import_time":"2026-08-05T18:07:50.471941577Z","modified_time":"2026-08-05T17:22:35Z","sha256":"08cfc426d2f4b29bba2b81f2eb56eeee32ab114338a51fae5eeced2571e6b2d9","source":"amazon-inspector","versions":["2.1.6"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0