目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

shadowx-fca

MAL-2026-13457
2026-08-06 23:29:21
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in shadowx-fca (npm)

凭据/密钥窃取文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
251
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmshadowx-fca10.0.0
npmshadowx-fca10.1.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T23:29:21Z","published":"2026-08-06T19:48:01Z","schema_version":"1.7.4","id":"MAL-2026-13457","summary":"Malicious code in shadowx-fca (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5e05ec19966fd3fff65969ab898a3b25da7e1fa0baf271ee9b75dadad8513c27)\nThe package advertises a Facebook Chat API (FCA) client. Its default-exported login() function accepts email, password, and an optional 2FA secret and, via loginViaAPI/tokensViaAPI, POSTs those credentials to https://minhdong.site/api/v1/facebook/login_ios rather than authenticating directly against Facebook. The destination is set as the default apiServer in module/config.js (defaultConfig.apiServer = \"https://minhdong.site\") and loadConfig executes at import time from module/login.js, so any consumer that does not explicitly override apiServer sends plaintext Facebook email, password, and TOTP seed to this third-party host. The remote endpoint returns a Facebook uid, access token, and cookies that are then used to impersonate the account. The domain minhdong.site is unrelated to Facebook and to the declared npm publisher.\n","affected":[{"package":{"ecosystem":"npm","name":"shadowx-fca"},"versions":["10.0.0","10.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"module/loginHelper.js","sha256":"58ddcfdf87baa17521eeaae8f738ea50450cbbbaeba8b502bfda06f497653d73","tlsh":"7643b60d31fb202905732078678ba111756ae4533689cde9bb9ca3346f85529cebf7cb"},{"path":"module/config.js","sha256":"bf4b31532529bac1e438b32553d68cb4ada6aa555758876a95f166aecd00f2c9","tlsh":"7b11ef0315ff6673055989a0e1df10123d42c7c7210fb694a28cb65caf4e1a595f36ec"}],"package_integrity":[{"filename":"shadowx-fca-10.0.0.tgz","hashes":{"sha1":"e2eb7c0e9b085a35446a359c43832bcb949d56e9","sha512_sri":"sha512-blKYocZaE3hyyz18lTy25DGfRzQfBiAic+9ioRey/UgToeZmm/D3EAL54l2emgsh82cHj2+ckbvaiqG72kUSIw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/shadowx-fca/v/10.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/shadowx-fca/v/10.1.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016818","import_time":"2026-08-06T23:25:10.870574299Z","modified_time":"2026-08-06T19:48:01Z","sha256":"5e05ec19966fd3fff65969ab898a3b25da7e1fa0baf271ee9b75dadad8513c27","source":"amazon-inspector","versions":["10.0.0"]},{"id":"IN-MAL-2026-016819","import_time":"2026-08-06T23:25:10.898791767Z","modified_time":"2026-08-06T19:48:12Z","sha256":"8973ae32a1add1000f7914e9a86c0af54d24e70f3cf5610c3dcdf547bc20d76c","source":"amazon-inspector","versions":["10.1.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0