目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@aubea/mars

MAL-2026-13415
2026-08-06 14:21:50
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @aubea/mars (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
18
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@aubea/mars1.0.0
npm@aubea/mars1.1.0
npm@aubea/mars1.2.0
npm@aubea/mars1.2.10
npm@aubea/mars1.2.11
npm@aubea/mars1.2.12
npm@aubea/mars1.2.2
npm@aubea/mars1.2.3
npm@aubea/mars1.2.4
npm@aubea/mars1.2.6
npm@aubea/mars1.2.7
npm@aubea/mars1.2.8
npm@aubea/mars1.2.9
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T14:21:50Z","published":"2026-08-06T13:39:10Z","schema_version":"1.7.4","id":"MAL-2026-13415","summary":"Malicious code in @aubea/mars (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bdc44d9f879ce07c857e122c24664d6ae0445cb55aceeeb12c898d65898f7617)\nWhen invoked as its CLI (npx @aubea/mars), the package opens a WebSocket connection to a hardcoded third-party relay at wss://cho100.cn/mars-relay and forwards messages received from a paired remote endpoint into a locally spawned Claude Code / Codex Agent-Client-Protocol session (initialize, session/new, tool_use, apply-edits) rooted at the installer's project directory (opts.cwd). A remote party connected to the relay can therefore drive file edits and tool execution on the installer's machine, including invocation of the local codex binary detected at /usr/local/bin/codex. The relay host cho100.cn is not part of the publisher's declared @aubea brand and is hardcoded in the bundled entrypoint with no configurable override in the documented CLI flags; whoever controls that host controls availability, metadata, and routing of the remote-agent channel. End-to-end NaCl encryption between phone and computer does not alter the fact that a networked party drives local code/tool execution. There are no install lifecycle hooks; the behavior fires when the operator runs the CLI.\n","affected":[{"package":{"ecosystem":"npm","name":"@aubea/mars"},"versions":["1.2.12","1.2.11","1.0.0","1.1.0","1.2.8","1.2.2","1.2.9","1.2.10","1.2.6","1.2.3","1.2.4","1.2.0","1.2.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/mars.mjs","sha256":"493c2b9ca1717d94e67c7c8f819b87a3c6f2ac8f53a0f2bcb626dd4164572709","tlsh":"ecf33a01b3a9657647ecb3d168bf4606b3b488745408440eb778d8ee5bacd82e1bef74"}],"package_integrity":[{"filename":"mars-1.2.12.tgz","hashes":{"sha1":"40dacfc9589b41a73ca8343f81c230202743cfb4","sha512_sri":"sha512-j7EA5wEUftoQE3qYoYCRTdsdCHOfQ66A8LBJW2nR7ZA5/K7Xp4/fP4j7vqIcHMeDTaDGaiS23+nrvoiSchJt6g=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.12"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.11"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@aubea/mars/v/1.2.7"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016493","import_time":"2026-08-06T14:19:52.231652611Z","modified_time":"2026-08-06T13:40:33Z","sha256":"006755590b6d2fdb396f9ddb138f7c00ebc4bd9ecb870b3267561e70e55ea8d1","source":"amazon-inspector","versions":["1.2.12"]},{"id":"IN-MAL-2026-016496","import_time":"2026-08-06T14:19:52.340894262Z","modified_time":"2026-08-06T13:40:57Z","sha256":"188fb328579315cdd5a2389776bd63499dd3e06c77b38fc24b2bf4e75d408f03","source":"amazon-inspector","versions":["1.2.11"]},{"id":"IN-MAL-2026-016494","import_time":"2026-08-06T14:19:52.26598732Z","modified_time":"2026-08-06T13:40:41Z","sha256":"2247b4e7c99823dd666d1f9436504a3b757de5941121ff6702b3909bc70a9f63","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-016495","import_time":"2026-08-06T14:19:52.305990777Z","modified_time":"2026-08-06T13:40:49Z","sha256":"4ca250d88587f6bd31710da3b621a944d9ada2792610e31fdaef60e55e152179","source":"amazon-inspector","versions":["1.1.0"]},{"id":"IN-MAL-2026-016485","import_time":"2026-08-06T14:19:51.775618278Z","modified_time":"2026-08-06T13:39:18Z","sha256":"8ed4b5323512272a66a7a860c231bce2a86205e4bfa5e5d1309fbf7caf705400","source":"amazon-inspector","versions":["1.2.8"]},{"id":"IN-MAL-2026-016491","import_time":"2026-08-06T14:19:52.044953861Z","modified_time":"2026-08-06T13:40:12Z","sha256":"990fe474db39f6565c44b22175f8a89cdd90e88a913f92e7e62d4b4840c617f9","source":"amazon-inspector","versions":["1.2.2"]},{"id":"IN-MAL-2026-016487","import_time":"2026-08-06T14:19:51.878502481Z","modified_time":"2026-08-06T13:39:34Z","sha256":"9ab3edd366f7dfd9c00b9d1caa1a409077ebd99fffa875f7839a0d58ccd043d3","source":"amazon-inspector","versions":["1.2.9"]},{"id":"IN-MAL-2026-016497","import_time":"2026-08-06T14:19:52.41818978Z","modified_time":"2026-08-06T13:41:04Z","sha256":"f79ef019d6fa2f40aaeeba1fb903dd2aca854b73915f4cc4e616919b781e3108","source":"amazon-inspector","versions":["1.2.10"]},{"id":"IN-MAL-2026-016488","import_time":"2026-08-06T14:19:51.922425119Z","modified_time":"2026-08-06T13:39:45Z","sha256":"f7f3c5974cbe44835680d0f2cbc3eb6af69914647b098037fe674f9a8f094dfe","source":"amazon-inspector","versions":["1.2.6"]},{"id":"IN-MAL-2026-016490","import_time":"2026-08-06T14:19:52.002722581Z","modified_time":"2026-08-06T13:40:04Z","sha256":"068cd7ec9976d035121953828e91137d5dc9124fb8cce25517b60126b417b33e","source":"amazon-inspector","versions":["1.2.3"]},{"id":"IN-MAL-2026-016489","import_time":"2026-08-06T14:19:51.968669564Z","modified_time":"2026-08-06T13:39:54Z","sha256":"bdc44d9f879ce07c857e122c24664d6ae0445cb55aceeeb12c898d65898f7617","source":"amazon-inspector","versions":["1.2.4"]},{"id":"IN-MAL-2026-016484","import_time":"2026-08-06T14:19:51.747771679Z","modified_time":"2026-08-06T13:39:10Z","sha256":"c6a020101e6fc72ab6b8ba0e6fe75933c0401c21beedca849f711ca5f8d1f63c","source":"amazon-inspector","versions":["1.2.0"]},{"id":"IN-MAL-2026-016492","import_time":"2026-08-06T14:19:52.118299768Z","modified_time":"2026-08-06T13:40:23Z","sha256":"d39fef25ebfb2e0eabad34d0914ac8daddd2a6588ff700f504eff6d06bca270a","source":"amazon-inspector","versions":["1.2.7"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0