目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@activepieces/piece-google-forms

MAL-2026-13396
2026-08-06 14:21:51
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @activepieces/piece-google-forms (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
18,289
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@activepieces/piece-google-forms0.5.5
npm@activepieces/piece-google-forms0.5.6
npm@activepieces/piece-google-forms0.5.7
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13396","published":"2026-08-06T12:57:07Z","modified":"2026-08-06T14:21:50.602081315Z","summary":"Malicious code in @activepieces/piece-google-forms (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (06d347d6252c2a1bb21b4318c0a319be36d60a95b4146d91108cee13d52c5759)\nThe published tarball for @activepieces/piece-google-forms 0.5.7 contains src/index.js which imports child_process, invokes ping-style OS command execution (line 38), and issues hardcoded HTTP POST requests (lines 25, 38). This co-occurrence — child_process command execution combined with network POST to a hardcoded destination inside a piece module that is loaded when the Activepieces host requires it — matches the shape of an installer-side command-execution and data-exfiltration payload rather than the ordinary Google Forms API integration the package advertises. A legitimate Google Forms piece would call the Google Forms REST API via the piece framework's HTTP helpers; it would not shell out or ping remote hosts. The package's name and scope also resemble the legitimate @activepieces/* piece ecosystem, which increases the likelihood that the release is a lookalike or a compromised publish rather than a benign integration.\n","affected":[{"package":{"name":"@activepieces/piece-google-forms","ecosystem":"npm"},"versions":["0.5.7","0.5.6","0.5.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/index.js","sha256":"e61a9248781be7d08a75875c673bda173807f1bccd6a24d1c346c3e8d7f4c8a3","tlsh":"18944c85b7e2b4b243e761f0e03b4506f3799854845c4478f768cdeb28e588a92bbf35"}],"package_integrity":[{"filename":"piece-google-forms-0.5.7.tgz","hashes":{"sha1":"1fb8dadff825277164a32af7cbe44ae60c2f30fe","sha512_sri":"sha512-I9MrcQ0oyNZpF6k792pLQ6qIRjLHOvQyl0/pvgqhNy2yQcyaITVP2hjrPRgrAVeHM1QdOfrJ615jahjAkbhpYw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@activepieces/piece-google-forms/v/0.5.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@activepieces/piece-google-forms/v/0.5.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@activepieces/piece-google-forms/v/0.5.5"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016274","import_time":"2026-08-06T13:09:09.278052481Z","modified_time":"2026-08-06T12:57:07Z","sha256":"06d347d6252c2a1bb21b4318c0a319be36d60a95b4146d91108cee13d52c5759","source":"amazon-inspector","versions":["0.5.7"]},{"id":"IN-MAL-2026-016381","import_time":"2026-08-06T14:19:46.1952632Z","modified_time":"2026-08-06T13:17:38Z","sha256":"c7434d6602ed97900763a5588c6ce5588cc4943751f1b52db1f854084f1b321f","source":"amazon-inspector","versions":["0.5.6"]},{"id":"IN-MAL-2026-016385","import_time":"2026-08-06T14:19:46.417646629Z","modified_time":"2026-08-06T13:18:21Z","sha256":"b4658e5ce47d286606492b92743e913f4cf585ade6a95bd9ae26a46ddcb1672f","source":"amazon-inspector","versions":["0.5.5"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0