目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@ks-video/kwai-player-web

MAL-2026-13433
2026-08-06 16:25:56
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @ks-video/kwai-player-web (npm)

凭据/密钥窃取安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@ks-video/kwai-player-web9.1.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T16:25:56Z","published":"2026-08-06T16:25:56Z","schema_version":"1.7.4","id":"MAL-2026-13433","summary":"Malicious code in @ks-video/kwai-player-web (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (189f106b356a246462f37d1199e1be9191a00724014f74d1ac2a39c94c5a8222)\nOn `npm install`, the package's `postinstall` hook runs `scripts/telemetry.js`, which collects installer-side reconnaissance — `os.hostname()`, `os.userInfo().username`, current working directory, all network interface addresses (including internal IPs from `os.networkInterfaces()`), Node.js version, and the full list of environment variable names via `Object.keys(process.env)` — and POSTs it over plain HTTP to a hardcoded endpoint at `http://telemetry.debugnotyja.com/api/v1/install`. The destination domain `debugnotyja.com` has no relationship to the declared publisher (Kwai / @ks-video) and is not a documented telemetry endpoint for that vendor. Environment variable name enumeration and internal network topology disclosure are strong follow-on-targeting signals; the `telemetry` label on the script does not equate to installer consent, and plain-HTTP transport additionally exposes the collected data to any on-path observer.\n","affected":[{"package":{"ecosystem":"npm","name":"@ks-video/kwai-player-web"},"versions":["9.1.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/telemetry.js","sha256":"3a1fa260f74a0fedd38ca5a7ef54a38cf4299fa05e6f4a46dd3cf9caddf5e6e1","tlsh":"c62168a151f1145427ab2190b066181262f2d0137807f8ec75e813e62fdedf880f9749"}],"package_integrity":[{"filename":"kwai-player-web-9.1.2.tgz","hashes":{"sha1":"7ce5704981ee62cd4be2e1df23bd444673766ad6","sha512_sri":"sha512-Rq5Hk2FhM4u+ezguUarr7CSZThFbVG4DMEe1oWsJSVdixN9n5v1N45ezld7YSrl4KorcsBBfs/EAcJm9rlmAww=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ks-video/kwai-player-web/v/9.1.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016695","import_time":"2026-08-06T18:09:07.429228327Z","modified_time":"2026-08-06T16:25:56Z","sha256":"189f106b356a246462f37d1199e1be9191a00724014f74d1ac2a39c94c5a8222","source":"amazon-inspector","versions":["9.1.2"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0