目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

devplatform-eslint-config

MAL-2026-13544
2026-08-07 12:25:53
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in devplatform-eslint-config (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmdevplatform-eslint-config35.8.9
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-07T12:25:53Z","published":"2026-08-07T12:25:53Z","schema_version":"1.7.4","id":"MAL-2026-13544","summary":"Malicious code in devplatform-eslint-config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (de0fcdb30a4308ee477f432e1bcc665e8ee45f3dd36dd02f22089a4b9e2a69f9)\ndevplatform-eslint-config@35.8.9 ships no ESLint configuration despite its name and description. Requiring the package loads _compat.js, which on import selects a payload path based on OS/architecture (linux_x64, linux_arm64, darwin, win32), fetches an opaque native binary over HTTPS from a rotating set of Cloudflare Workers hosts whose names are assembled at runtime by joining split string fragments (oob-worker.cf102-baf.workers.dev, oob-worker.cf103-070.workers.dev, oob-worker.cf99-9b3.workers.dev, oob-worker.cf100-416.workers.dev), with a DNS-TXT covert-channel fallback that reassembles base64 chunks from TXT records under sdk.dl.wel1.ru, ext.dl.wel1.ru, pkg.dl.wel1.ru, and net.dl.wel1.ru. The fetched bytes are written to a temporary path with a decoy filename (e.g. dotnet_diag_*.exe,.cache_*), chmod 0755, and executed via a detached child process (cp.spawn('/bin/sh',['-c', fp+' &'], {detached:true}) on POSIX, cmd.exe start /b on Windows). lib/telemetry.js contains duplicate fetch-write-chmod-spawn primitives. Runtime string assembly of C2 hostnames hides destinations from static analysis, and the ESLint-config identity is a cover story unrelated to the shipped code.\n","affected":[{"package":{"ecosystem":"npm","name":"devplatform-eslint-config"},"versions":["35.8.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"_compat.js","sha256":"ade3278944e896438532b00f202ac4ff11cfda4c4c050a45e698e4d9840cec94","tlsh":"1ba1955a156670088bb0dbe4c7175416f6abf6632780c298fb6ca5884fb356883b1dfc"},{"path":"package.json","sha256":"70413de21a15d2f160031a45559fcab67a72a1c18051d5bd8488f4a89328ecee","tlsh":"b3c02223c120ac2301b01d41dce119273ba21f1f10229c0eb673321c02e457100de312"}],"package_integrity":[{"filename":"devplatform-eslint-config-35.8.9.tgz","hashes":{"sha1":"58c61da62d23635c70d38c1ea2572b1e58ec5ad1","sha512_sri":"sha512-N3IsQYzwLm4iDrfO8WGGSEnrsuzN+nDBndiNXNOFxOzlbAC8tOaQk8F4/QW8shIwOLV0xTaCfKi+eAu4amCBNg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/devplatform-eslint-config/v/35.8.9"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016977","import_time":"2026-08-07T12:51:20.612862599Z","modified_time":"2026-08-07T12:25:53Z","sha256":"de0fcdb30a4308ee477f432e1bcc665e8ee45f3dd36dd02f22089a4b9e2a69f9","source":"amazon-inspector","versions":["35.8.9"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0