目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

forge-gas-diff

MAL-2026-13516
2026-08-08 00:55:08
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in forge-gas-diff (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0archivedVIP 下载
1.0.1unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmforge-gas-diff1.0.0
npmforge-gas-diff1.0.1
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13516","published":"2026-08-07T12:09:35Z","modified":"2026-08-08T00:55:07.646091193Z","summary":"Malicious code in forge-gas-diff (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4b1f6143f5a7c6106ab4ba0a21a6adaf9020e332835b1e528de6f36b64537734)\nindex.js is advertised as a Foundry gas-report diff utility but on module load / CLI run schedules a setTimeout of 259,200,000 ms (3 days) that calls https.get against https://gist.githubusercontent.com/opensource-crypto/3946ef88aa057c9d10f1a7d80391d164/raw/default.json. The gist is hosted on a GitHub account (opensource-crypto) unrelated to the declared package publisher (danird9). If the fetched JSON contains a `c2` field, the value is persisted to ~/.forge-gas-diff.remote for later use. A separate getInstallId() routine writes a per-host UUID to ~/.forge-gas-diff, providing a stable install fingerprint. None of this behavior — outbound network fetch, install-ID generation, remote-config persistence, or a field literally named `c2` — has any relationship to the advertised gas-diff functionality and is not documented in the package. The gist is author-mutable, so the content delivered to installers can be changed at any time without republishing the package; the 3-day delay places the fetch well outside typical install-time sandboxing windows. The mechanism is the staging half of a remote-config-driven dropper: a hidden update channel keyed to attacker-editable content on a third-party host, with persistence to a well-known filesystem path on the installer's machine.\n","affected":[{"package":{"name":"forge-gas-diff","ecosystem":"npm"},"versions":["1.0.0","1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"8651a3e22896696142fc14d510aac386d3829d5376c2c33b4aacc56b39a7721f","tlsh":"38712fe438fb72a0028322ed6b8b6519b131e0333009c994fa8de6916f955349797eec"}],"package_integrity":[{"filename":"forge-gas-diff-1.0.0.tgz","hashes":{"sha1":"e0fa210630abe85cb00178c23a6f20276a6b8551","sha512_sri":"sha512-R+o/Lsf73lMSd6jCJQdyTMLGEe2y0PlDffb+u2tciAnYdTJJ6P53CFAGHCtVn1ZZOE+rgILPaRxHBuZW/Aqd+w=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/forge-gas-diff/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/forge-gas-diff/v/1.0.1"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016870","import_time":"2026-08-07T12:23:25.114212002Z","modified_time":"2026-08-07T12:09:35Z","sha256":"4b1f6143f5a7c6106ab4ba0a21a6adaf9020e332835b1e528de6f36b64537734","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-017199","import_time":"2026-08-08T00:53:10.172517816Z","modified_time":"2026-08-08T00:52:29Z","sha256":"8af09f105251f3c5b76ac9a11592a9af1cfb901b073472c57362c51c0a85fd2a","source":"amazon-inspector","versions":["1.0.1"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0