目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

bigops-telephony-mock

MAL-2026-13494
2026-08-07 12:11:49
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in bigops-telephony-mock (npm)

安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmbigops-telephony-mock35.7.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-07T12:11:49Z","published":"2026-08-07T12:11:49Z","schema_version":"1.7.4","id":"MAL-2026-13494","summary":"Malicious code in bigops-telephony-mock (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ccbd56ae20f9cc922c12df25456654a649c9bbc963aae4fa95e027f97628c45b)\nRequiring the package (index.js ->./setup) triggers setup.js, which reconstructs destination hostnames from split string fragments (e.g. oob-worker.cf101-adf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev) with a DNS-TXT fallback across sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru, downloads a platform-specific binary via https.get, writes it to a disguised path under /tmp or %TEMP% (names such as analytics_state, dotnet_diag_*.exe,.cache_*), fs.chmodSync's it to 0755, and cp.spawn's it detached via /bin/sh -c '<file> &' or cmd.exe /c start /b. No version pin, no hash or signature verification, and destinations are assembled at runtime to defeat static inspection; child_process itself is required as \"child_\" + \"process\" in lib/telemetry.js. A second copy of the same download->base64-decode->chmod 755->spawn /bin/sh loader is bundled under lib/telemetry.js (approximately 81KB) framed as a telemetry SDK. The behavior fires on any require()/import of the package, gated only by an opt-out env var and a TTL marker file, so a normal npm install followed by loading the module causes attacker-controlled code to execute on the installer's machine.\n","affected":[{"package":{"ecosystem":"npm","name":"bigops-telephony-mock"},"versions":["35.7.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"setup.js","sha256":"354e3b3034f3f0752ffdbfeae03cfb6da5938b19b54f751cfc3f192aeb580a35","tlsh":"9aa1a79a1266b1188fb0abe4c71b8816f61bf2a33781c284fb5c65845f735148372efc"},{"path":"lib/telemetry.js","sha256":"7f71a0f07b9f72570746aaacb191fb3d313fa373cef63b3ad65266b6d3aa49e4","tlsh":"5e835055566a242186b2b368df234107ff3685272643429dbafc82dc1fbd72092a5ffc"}],"package_integrity":[{"filename":"bigops-telephony-mock-35.7.2.tgz","hashes":{"sha1":"0598b325f3496cb29ab1f535148f4f4601cd27f9","sha512_sri":"sha512-pYwY8e7fOrRPQdrcHtxHpeauaR0uI9cDP0BwZdDAmfP5tPxkmSUy8pwZh+Ncy29Awv6AsY2MvLTFkA2IufFCyg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bigops-telephony-mock/v/35.7.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016878","import_time":"2026-08-07T12:23:25.447470807Z","modified_time":"2026-08-07T12:11:49Z","sha256":"ccbd56ae20f9cc922c12df25456654a649c9bbc963aae4fa95e027f97628c45b","source":"amazon-inspector","versions":["35.7.2"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0