目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

squeez

MAL-2026-13458
2026-08-06 23:29:21
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in squeez (npm)

安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
265
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmsqueez1.38.0
npmsqueez1.40.0
npmsqueez1.42.1
npmsqueez1.44.1
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-06T23:29:21Z","published":"2026-08-06T19:46:25Z","schema_version":"1.7.4","id":"MAL-2026-13458","summary":"Malicious code in squeez (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a953148095c35441147f1622c4810e0b946e5d120a74cfbe14f1771276a731d7)\nsqueez@1.38.0 declares a postinstall hook (\"postinstall\": \"node install.js\") that runs automatically on npm install. install.js imports child_process, fs, https, and os; branches on process.platform; reads os.homedir(); performs fs.existsSync/readFileSync checks against paths under the user's home directory; and issues https.get requests to raw.githubusercontent.com URLs. The combination of an install-time lifecycle script, filesystem reads of home-directory paths, process spawning capability, and fetching content from a mutable third-party host at install time constitutes an install-time remote-content-fetch-and-execute pattern with home-directory reconnaissance. Fetching executable content from raw.githubusercontent.com at install time is a mutable, unpinned delivery channel: the current content of those URLs can change at any time without a package release, and the fetched bytes are handled inside a script that also has child_process available.\n","affected":[{"package":{"ecosystem":"npm","name":"squeez"},"versions":["1.40.0","1.44.1","1.42.1","1.38.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"install.js","sha256":"f13107285ab0d05bbaab4f56b51e042e6078e3a8313393e34196ebc99923634f","tlsh":"20e153fa44f752387db2e17cd60b215a1537a1133226ea70717df240afcc1a845a6afa"},{"path":"package.json","sha256":"e9534be7395668d5326f48780a444a774279bf30ef51481ac1e4f2a6cf846569","tlsh":"0d114864c4742eb32ad87b94c99a2059a2350947a9603c2a736fc31c5b8c1ab25bf57d"}],"package_integrity":[{"filename":"squeez-1.40.0.tgz","hashes":{"sha1":"4a41da65884c85232c1890c33bfab55917e350c3","sha512_sri":"sha512-I/x0i/wE8ORytPV7v8TH8Hu3Nss3Ww1v9pMDhKc4HPLbhE2ClfSDqWJWb7nn0G0iyhpZozkYWM8U9q2ORPaLHQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/squeez/v/1.40.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/squeez/v/1.44.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/squeez/v/1.42.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/squeez/v/1.38.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016815","import_time":"2026-08-06T23:25:10.760161255Z","modified_time":"2026-08-06T19:46:35Z","sha256":"0b13d20d19ea0a8d54c03338cee13994ca570c587fb809a035fd7cf3f72e27cc","source":"amazon-inspector","versions":["1.40.0"]},{"id":"IN-MAL-2026-016814","import_time":"2026-08-06T23:25:10.683637165Z","modified_time":"2026-08-06T19:46:25Z","sha256":"4991cb893b5cb093cad80227f428e2161aa36cdfd918aa12009818199b88ecf5","source":"amazon-inspector","versions":["1.44.1"]},{"id":"IN-MAL-2026-016817","import_time":"2026-08-06T23:25:10.816694675Z","modified_time":"2026-08-06T19:46:54Z","sha256":"779daf2d38cd96af82b4dc2dd8f29d362dc5e5c0db1340134a8de2e5c8ce21c9","source":"amazon-inspector","versions":["1.42.1"]},{"id":"IN-MAL-2026-016816","import_time":"2026-08-06T23:25:10.786740917Z","modified_time":"2026-08-06T19:46:44Z","sha256":"a953148095c35441147f1622c4810e0b946e5d120a74cfbe14f1771276a731d7","source":"amazon-inspector","versions":["1.38.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0