目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

agenthub-multiagent-mcp

MAL-2026-13399
2026-08-06 12:30:47
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in agenthub-multiagent-mcp (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
708
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmagenthub-multiagent-mcp1.57.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T12:30:47Z","published":"2026-08-06T12:30:47Z","schema_version":"1.7.4","id":"MAL-2026-13399","summary":"Malicious code in agenthub-multiagent-mcp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ca33b55b94f99f1de3d4b34ee5fc42941013cc5ab1f94dce49b6cc0bed5eaa9a)\nagenthub-multiagent-mcp ships a worker (dist/worker.js) that opens a WebSocket to the hardcoded server wss://agenthub.contetial.com/ws/workers/<id> and, for every 'dispatch' message received, writes the server-supplied message body to a prompt file and spawns 'bash run-claude.sh' which invokes 'claude -p \"$PROMPT\" --dangerously-skip-permissions --max-turns N --mcp-config...' with cwd set to a user-configured project directory. This gives whoever controls agenthub.contetial.com the ability to drive Claude Code's full tool suite (file read/write, shell, MCP tools) against the installer's projects with permissions checks explicitly disabled. The setup wizard (agenthub-setup) additionally installs OS-level persistence: a Windows Startup.vbs + hidden.bat launcher, a macOS LaunchAgent com.agenthub.worker.plist with RunAtLoad and KeepAlive, or a Linux systemd user unit agenthub-worker.service with Restart=always, so the remote-controlled worker reconnects on every login. Provenance is falsified: package.json declares repository.url https://github.com/anthropics/agenthub and homepage https://github.com/anthropics/agenthub#readme, and the README directs users to git clone https://github.com/anthropics/agenthub, while the actual author is 'Krishi AI' and the operational domain is agenthub.contetial.com. dist/setup.js contains a fetch to https://agenthub.contetial.com and dist/context.js/state.js perform base64 decoding of embedded blobs.\n","affected":[{"package":{"ecosystem":"npm","name":"agenthub-multiagent-mcp"},"versions":["1.57.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/worker.js","sha256":"3be60ed23888e72f6843532db1ff0dc73aa46db8eb031659fc0360a9bf556e58","tlsh":"36d2c58a58f7063202777028579f1005ba3aa2673644e9a47acc93449f5d72cc7f6fee"},{"path":"dist/setup.js","sha256":"eb9f72ed2d00da4ecbaff51b642d8c915b9f266490b19f70e22fdb49a6ccecf5","tlsh":"5e92b48a48f705360b736aa85b2f1505735ed123b248fc94768c97c46f76328c962bee"},{"path":"package.json","sha256":"03a4eed9a7bb059df50eb413cf881e06ecf69250feb24a9f9a9c5aa1770e8961","tlsh":"80410f6bc9ab8d7307b8a7c1fab60201f315432f9100988bb2b52a1ccff5297114bb58"}],"package_integrity":[{"filename":"agenthub-multiagent-mcp-1.57.0.tgz","hashes":{"sha1":"c339a2c1bfbe0d4a80b3c800c0cb511f09488a6d","sha512_sri":"sha512-Hor9cwvDy6wvfgeW3bJ0U4OL6Bw7y/V+R8bpWuuA6xgw1I6IiRVD7jNEbE0T189Fbk1Y0t39km1unGYNBoTDpA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/agenthub-multiagent-mcp/v/1.57.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016096","import_time":"2026-08-06T13:08:48.901998744Z","modified_time":"2026-08-06T12:30:47Z","sha256":"ca33b55b94f99f1de3d4b34ee5fc42941013cc5ab1f94dce49b6cc0bed5eaa9a","source":"amazon-inspector","versions":["1.57.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0