目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

express-chai

MAL-2026-13446
2026-08-06 19:11:04
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in express-chai (npm)

凭据/密钥窃取
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmexpress-chai3.7.9
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T19:11:04Z","published":"2026-08-06T19:11:04Z","schema_version":"1.7.4","id":"MAL-2026-13446","summary":"Malicious code in express-chai (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (34482e23635422fb5ca5632e68708453f1c99317a31e5e8346c75c4d3466560f)\nexpress-chai presents itself as an Express logger middleware impersonating pino, but its exported middleware factory invokes lib/caller.js which decodes a base64-obfuscated URL (https://gray-dyane-31.tiiny.site/index.json) stored in lib/const.js, fetches a JSON payload via axios with a base64-encoded `dev-secret-key` header, and passes the response's `cookie` field to `new Function.constructor(\"require\", s)`, then invokes the resulting function with the local `require`. This grants the operator of the anonymous tiiny.site host arbitrary code execution inside the installer's Node.js process at middleware setup time, with full access to `require` and the surrounding application context. The destination URL and secret header are base64-encoded rather than plain configuration, and the package's naming, keywords (fast, logger, stream, json), and pino-mirroring script names disguise a remote code loader as a well-known logging library.\n","affected":[{"package":{"ecosystem":"npm","name":"express-chai"},"versions":["3.7.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/caller.js","sha256":"cb2c1b0cdf9cb22b28726542c4ce033d2ad9197bbc6294bb176051a3e42355c4","tlsh":"7df0784e31fd205c02a222e86b2b95336091f4623406d8c4374cc3535fe5aad5ba3ade"},{"path":"lib/const.js","sha256":"2d5b58230cd5bf2093cde8b7bf751fee8eee1d76acc4df2a8fb71796cf40dcf3","tlsh":"51d022d310a02440607013b2a61da901f582e8af0c8221183aea64840a366aa3880d6f"},{"path":"index.js","sha256":"96902515c575ebdf7adf510de5ad14e9df32eb6db930949dcf225a67318582be","tlsh":"dc111091b4f5514a064dd4d9b128a526bcf7d83732067db0aaec474927ce10c11b1bd3"}],"package_integrity":[{"filename":"express-chai-3.7.9.tgz","hashes":{"sha1":"34cc3aeed33a9fbf26e18258d30f649b3922d85e","sha512_sri":"sha512-J3A8e/IC0D3MuksmnYvOKLzYegus2NeQ8/ypH5Oo1IJsQFzE9/AXT0vez7TmsZ0v26NKUH4nnnKirT3yntj+4g=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/express-chai/v/3.7.9"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016744","import_time":"2026-08-06T23:25:07.094269835Z","modified_time":"2026-08-06T19:11:04Z","sha256":"34482e23635422fb5ca5632e68708453f1c99317a31e5e8346c75c4d3466560f","source":"amazon-inspector","versions":["3.7.9"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0