目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

golaaa

MAL-2026-13392
2026-08-19 09:17:17
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in golaaa (npm)

凭据/密钥窃取文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0archivedVIP 下载
1.0.3unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmgolaaa1.0.0
npmgolaaa1.0.3
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13392","published":"2026-08-06T12:13:09Z","modified":"2026-08-19T09:17:16.518089053Z","summary":"Malicious code in golaaa (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (43f9a2a9514f30f4def10f6a0a21b4abf4f882fa29a45c6b7c93e96490f49c13)\nThe package's main module (cdp_inject.js) runs on require. It disables TLS certificate verification process-wide (process.env.NODE_TLS_REJECT_UNAUTHORIZED='0'), taskkills and re-launches a local browser executable at %USERPROFILE%\\AppData\\Local\\Programs\\testpad\\testpad.exe with --remote-debugging-port=9222, and connects to it via the Chrome DevTools Protocol on 127.0.0.1:9222. It then injects a script into every attached page that captures document.body.innerText and the active editor's contents on user gestures, base64-encodes the payload, and POSTs it to the hardcoded endpoint https://ai-script.test0ing7.workers.dev/ (a Cloudflare Workers proxy that forwards to Groq). The response body from that remote endpoint is interpolated into a CDP Runtime.evaluate expression (window._rR(<remote JSON>)) and executed in the context of the user's browser pages, giving the remote endpoint arbitrary JavaScript execution in the victim's browser sessions (including CSP-restricted pages) with keystrokes auto-typed back into the page. A Groq API key is also embedded in the source, obfuscated with an XOR-over-base64 routine (_xd with key 'Mx7rLp2Qn') and POSTed as the 'key' field to the same proxy. The exfiltration destination is hardcoded and not caller-configurable, and the module load starts the polling loop with no opt-in.\n","affected":[{"package":{"name":"golaaa","ecosystem":"npm"},"versions":["1.0.0","1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"cdp_inject.js","sha256":"cea9a71f32d76323858615e08889cc52496702623b19ee4cdce1612ad978fc58","tlsh":"7c82e69760a6213585b6f3b99f538546f73ae023310103b4be5c86982ff28b48276fdd"}],"package_integrity":[{"filename":"golaaa-1.0.0.tgz","hashes":{"sha1":"75ad102f6d2387d693d1adf54a61031ff39f0694","sha512_sri":"sha512-stOg5PT7VzAi4XmwRUIEFfcdn/9tE/UAgvP+IwB5z2wxmjAqSj7ZeYixCVHZxLtQXc83R1pAWTn1GCjK3Tm/Fw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/golaaa/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/golaaa/v/1.0.3"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015990","import_time":"2026-08-06T12:16:02.7383252Z","modified_time":"2026-08-06T12:13:09Z","sha256":"01b6c227c2b9147d78df3a778d5de60d58b9cb115c6e7a7ce811143e05413ceb","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-018417","import_time":"2026-08-19T09:15:25.321049972Z","modified_time":"2026-08-19T09:14:32Z","sha256":"43f9a2a9514f30f4def10f6a0a21b4abf4f882fa29a45c6b7c93e96490f49c13","source":"amazon-inspector","versions":["1.0.3"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0