目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@depup/nuxt

MAL-2026-13625
2026-08-07 17:25:02
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @depup/nuxt (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
639
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
4.5.0-depup.0archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npm@depup/nuxt4.5.0-depup.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-07T17:25:02Z","published":"2026-08-07T17:25:02Z","schema_version":"1.7.4","id":"MAL-2026-13625","summary":"Malicious code in @depup/nuxt (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b0811cc3f28ee89cf1ab9a44155c55f9f590f4692bad740986dc00b67dbb8bb3)\nThis package presents itself as a routine Nuxt republish with dependency bumps, but ships two coordinated modifications that pull attacker-controlled code into the installer's Nuxt build environment. First, package.json injects a direct runtime dependency on \"@dxup/nuxt\": \"^0.5.3\" — a lookalike of the package's own @depup scope — which is not declared in the README or in changes.json among the advertised dep bumps (@nuxt/devtools, @unhead/vue, @vue/shared, devalue, nostics, rolldown-string, undici, unhead, unimport, vue) and does not exist in upstream nuxt@4.5.0. Second, dist/index.(m)js is tampered to push \"@dxup/nuxt\" into options._modules when experimental.typescriptPlugin is enabled, so when a consumer uses this package as their nuxt and runs the Nuxt build or dev server, @dxup/nuxt is auto-loaded as a privileged Nuxt module and executes arbitrary code in the build/dev context. The scope name and undocumented injection are consistent with dependency-graph smuggling under cover of a familiar Nuxt republish.\n","affected":[{"package":{"ecosystem":"npm","name":"@depup/nuxt"},"versions":["4.5.0-depup.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"932f6e8ddb11482a526932eed9685a1c3f5b6af4e530b8f585d333da96efa867","tlsh":"f064e8b1e79c371606f531d9993d40cfa9bcc272790dc8a6becc67f4268381dc2a6a54"},{"path":"package.json","sha256":"c5f100fcd5423d49b5682e5f6ca4e2865366956845cbfb4980ffd0c3e9dbe0de","tlsh":"cfc1bc24cca4cdd308d422f5a82a1142a61451874e18fd1c37dd47adaf0d6af32bfbae"}],"package_integrity":[{"filename":"nuxt-4.5.0-depup.0.tgz","hashes":{"sha1":"3d644d49e6a5f9efac21010f70a68e3e98325a67","sha512_sri":"sha512-hlKOjd3YN3Yk6BfQB8Ok4lq4ktmgrmPbOHsLtfaeyHEGFL+YIFP5NqDBZqF0BSvyId7qQd1fK8Tfr3TWqpmMHQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@depup/nuxt/v/4.5.0-depup.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017131","import_time":"2026-08-07T17:51:00.158602597Z","modified_time":"2026-08-07T17:25:02Z","sha256":"b0811cc3f28ee89cf1ab9a44155c55f9f590f4692bad740986dc00b67dbb8bb3","source":"amazon-inspector","versions":["4.5.0-depup.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0