目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

wormgpt-cli

MAL-2026-13466
2026-08-07 01:01:14
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in wormgpt-cli (npm)

凭据/密钥窃取文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0archivedVIP 下载
1.0.1unavailable
1.0.2unavailable
1.0.3unavailable
1.0.4unavailable
1.0.5unavailable
1.0.6unavailable
1.0.7unavailable
1.0.8unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmwormgpt-cli1.0.0
npmwormgpt-cli1.0.1
npmwormgpt-cli1.0.2
npmwormgpt-cli1.0.3
npmwormgpt-cli1.0.4
npmwormgpt-cli1.0.5
npmwormgpt-cli1.0.6
npmwormgpt-cli1.0.7
npmwormgpt-cli1.0.8
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13466","published":"2026-08-06T19:10:40Z","modified":"2026-08-07T01:01:14.391652127Z","summary":"Malicious code in wormgpt-cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (534ea1156519b64249657c1495faacdb3cc5d8e250a00e0dc2f8fd4e991af61c)\nThe package's bin entries (`wormgpt-cli`, `wormgpt`, `deepholegpt`, `wgpt`) map to `bin/victim.js`, which silently spawns a detached implant on any invocation (including `--help`/`--version`). The implant connects to a hardcoded C2 at http://13.60.13.215:7771 over an AES-256-GCM/HMAC-signed protocol with pool failover and a DNS TXT dead-drop channel (`protocol.js` `pollDnsDeaddrop`) that rotates the C2 URL and shared secret at runtime. On beacon, `implant.js` `gatherInfo()` collects hostname, user, OS, architecture, PID, cwd, home, LAN IP, admin flag, and a persistent victim_id, and accepts opcodes for shell/PowerShell execution, interactive PTY reverse shell, file up/download, keylogging (`GetAsyncKeyState` PowerShell loop), clipboard capture, screenshots, LAN lateral-movement scanning, privilege-escalation checks, and anti-forensics wipe. `stealers/browser.js` reads Chrome/Edge/Brave/Opera/Vivaldi Login Data SQLite databases, decrypts DPAPI-protected passwords via PowerShell with an AMSI bypass stub (`AMSI_BYPASS_B64` base64 blob run through `powershell -EncodedCommand`), parses Firefox `logins.json`, and regex-scans Discord/Chrome LevelDB for auth tokens (`/[\\w-]{24}\\.[\\w-]{6}\\.[\\w-]{27}|mfa\\.[\\w-]{84}/g`), exfiltrating results via C2 opcode OP_BROWSER_DATA. `persist.js` installs persistence across six autostart layers per OS: Windows HKCU/HKLM Run keys, Startup.lnk, WMI __EventFilter/CommandLineEventConsumer permanent subscription, scheduled tasks, and hidden `Windows Helper` directories via `attrib +H +S`; Linux XDG autostart, systemd --user units, `@reboot` crontab, shell RC injection (`.bashrc`/`.zshrc`/`.profile`/`.xinitrc`), and `/etc/rc.local`; macOS LaunchAgent plist with KeepAlive and Login Items via osascript. `loader.js` runs a watchdog sibling process (poll every 20s, `MAX_REVIVES = 50`) plus `uncaughtException` respawn to keep the implant alive.\n","affected":[{"package":{"name":"wormgpt-cli","ecosystem":"npm"},"versions":["1.0.0","1.0.3","1.0.8","1.0.4","1.0.7","1.0.2","1.0.5","1.0.1","1.0.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/implant/implant.js","sha256":"f43c7c2eb90ce5ce4e1985e940b8da0dede7eda683f1d4f83237e37e0bfe4b65","tlsh":"ec82958a7efb64344162f16216270019faaad0271709cdf47eac5794ff6433481feae9"},{"path":"src/implant/stealers/clipboard.js","sha256":"eb13c4e8c61c4a10dd91b589ef65714751556a5e02224e279b04e467f28869e1","tlsh":"146177c28ffbf4b08aa2dcb54803085ae97510724556da95765e449cef0fa3091fcf89"},{"path":"src/protocol.js","sha256":"181d064b60d4607595b474417dbb0c22c964543148b506f58bbfec628e7c0ff5","tlsh":"0512e7683ce5642401a2e8d956bb909bf61260033415e1b0ff4d4790afee93ca23fadd"}],"package_integrity":[{"filename":"wormgpt-cli-1.0.0.tgz","hashes":{"sha1":"6bc93888985a9068663ec6537ca17097324ab5a2","sha512_sri":"sha512-c4t07L2va7I5gSiRHAbCzZEVRW9a3YRYDKdqHmKWHXTckdHXle/qkDUNKDeU32Jyf1G+pnu8CYtt2tRQshvvaQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/wormgpt-cli/v/1.0.6"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016743","import_time":"2026-08-06T23:25:07.052435408Z","modified_time":"2026-08-06T19:10:40Z","sha256":"6f76eeb5f3df3c8ebc673a73d88aeb6dd0eb89b2b350a36023e2fe2a42eb8ed1","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-016865","import_time":"2026-08-07T00:59:23.177679581Z","modified_time":"2026-08-06T23:59:48Z","sha256":"c19fcfc558eeb517443b7175909cc46461cde81d1b21fb85453599ad152a0ea5","source":"amazon-inspector","versions":["1.0.3"]},{"id":"IN-MAL-2026-016861","import_time":"2026-08-07T00:59:22.795470011Z","modified_time":"2026-08-06T23:59:17Z","sha256":"eebdb11a91bed2a4772d539dc747d9e3ebbf691dda914003b5f8489f0adeeb8c","source":"amazon-inspector","versions":["1.0.8"]},{"id":"IN-MAL-2026-016866","import_time":"2026-08-07T00:59:23.278554169Z","modified_time":"2026-08-06T23:59:56Z","sha256":"f5b2b75cd854946d520e769fef83618dd912cde948ea954a51eb716661302702","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-016863","import_time":"2026-08-07T00:59:22.99668467Z","modified_time":"2026-08-06T23:59:33Z","sha256":"1e2405ae20c3c88dd3adeaa11ed725879aad3625226f4a252748daca8f0874a5","source":"amazon-inspector","versions":["1.0.7"]},{"id":"IN-MAL-2026-016867","import_time":"2026-08-07T00:59:23.381754662Z","modified_time":"2026-08-07T00:00:04Z","sha256":"534ea1156519b64249657c1495faacdb3cc5d8e250a00e0dc2f8fd4e991af61c","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-016864","import_time":"2026-08-07T00:59:23.083960016Z","modified_time":"2026-08-06T23:59:41Z","sha256":"56bfdc165a63f6eecd4e33262562a3b65da59da549298568c42e6b1e530f8860","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-016868","import_time":"2026-08-07T00:59:23.467747845Z","modified_time":"2026-08-07T00:00:13Z","sha256":"8b03000b5f21aa6e61de1a5bf5149d0059372d0663ffda561d2ea8df59062630","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-016862","import_time":"2026-08-07T00:59:22.902902659Z","modified_time":"2026-08-06T23:59:25Z","sha256":"a0ae945d716ee5032c1527fc139d67cd5dee3b155030441574fac459c27a14a6","source":"amazon-inspector","versions":["1.0.6"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0