目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@united-airlines-org/atmos-design-system

MAL-2026-13435
2026-08-06 23:46:08
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @united-airlines-org/atmos-design-system (npm)

安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@united-airlines-org/atmos-design-system*
npm@united-airlines-org/atmos-design-system40.0.0
npm@united-airlines-org/atmos-design-system41.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13435","published":"2026-08-06T00:00:00Z","modified":"2026-08-06T23:46:08.170180654Z","summary":"Malicious code in @united-airlines-org/atmos-design-system (npm)","details":"The package @united-airlines-org/atmos-design-system contains a malicious `preinstall` script in its package.json that runs automatically during installation. The script executes `curl` to send the machine's hostname, obtained via `uname -n` and base64-encoded, to the attacker-controlled endpoint `https://bxss.boll-sec.de/hostname_<base64-hostname>`. This exfiltrates host reconnaissance data to a remote server. All versions of the package are malicious.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5683e7389b9b288024f2c9827c3649d7b291996625265f6365535121fc1f431a)\nPackage @united-airlines-org/atmos-design-system@41.0.0 ships no library code — only a package.json whose `preinstall` script runs `/usr/bin/curl` to https://bxss.boll-sec.de/callb with base64-encoded values of `uname -n`, `ls` of the current directory, and `whoami` as query parameters. This fires automatically on `npm install`, sending the installer's hostname, working-directory listing, and username to an external, non-first-party host. The scope name resembles an internal United Airlines organization and the package contains no functional code beyond the beacon, matching the dependency-confusion pattern in which resolution of an internal package name pulls in an attacker-published public artifact.\n","affected":[{"package":{"name":"@united-airlines-org/atmos-design-system","ecosystem":"npm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["41.0.0","40.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"92e2ab0aa04991f6c31275498e8eab4907ffdff8b82abaffe05388af1c6e73f7","tlsh":"e1f0ec70d5591473dbc18e5708045a66a1905f1f09407c5597cb5178d1ce3f374f6b1c"}],"package_integrity":[{"filename":"atmos-design-system-41.0.0.tgz","hashes":{"sha1":"0925fd318c068b4dab437018e8ae9c393e655444","sha512_sri":"sha512-L4FGAOJB1S06i0P3v01li0WaBlYyFHnMufGadaw/tWzLKMTzgh/2k+Q+WJrWeIsSpNdj1t2fvxUvAAGjzQtH7g=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@united-airlines-org/atmos-design-system/v/41.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@united-airlines-org/atmos-design-system/v/40.0.0"}],"database_specific":{"iocs":{"domains":["bxss.boll-sec.de"]},"malicious-packages-origins":[{"id":"IN-MAL-2026-016750","import_time":"2026-08-06T23:25:07.441082535Z","modified_time":"2026-08-06T19:12:12Z","sha256":"5683e7389b9b288024f2c9827c3649d7b291996625265f6365535121fc1f431a","source":"amazon-inspector","versions":["41.0.0"]},{"id":"IN-MAL-2026-016751","import_time":"2026-08-06T23:25:07.500169229Z","modified_time":"2026-08-06T19:12:19Z","sha256":"6b82e32ac4430e26041e8e3df065620ea4bb58bc1a2a7c8bf1933e1760a77417","source":"amazon-inspector","versions":["40.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0