目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

localization-fixer

MAL-2026-13631
2026-08-08 00:55:08
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in localization-fixer (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.1unavailable
1.1.1archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmlocalization-fixer1.0.1
npmlocalization-fixer1.1.1
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-08T00:55:08Z","published":"2026-08-08T00:51:34Z","schema_version":"1.7.4","id":"MAL-2026-13631","summary":"Malicious code in localization-fixer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (72446c1307e81047c64d819d3485fa77062061c8c9d4d0b38b42e311137c8701)\nOn require of the package's main entry, a top-level `if (isServer) syncLanguageSystem()` fetches a JSON payload from https://api.jsonbin.io/v3/b/6a764665da38895dfec7cd5d and executes the returned `record.value` field as JavaScript, both by writing it to a temp file and running it via `child_process.fork` and via `new Function('require', payload)(require)` in a separate module-load IIFE that pulls https://api.jsonbin.io/v3/b/6a718a58da38895dfeb6e2ed. Both sinks pass the Node `require` to the constructed function, granting full Node capabilities to whatever the mutable jsonbin.io bin currently serves. Function and variable names (`syncLanguageSystem`, `LANG_SOURCE`, `lang_pass_key`) frame the fetch-and-exec as a localization-sync feature, but the advertised purpose of the package has no need to evaluate remote bytes. The jsonbin.io bins are attacker-mutable, so the payload delivered to any installer is arbitrary and can change at any moment.\n","affected":[{"package":{"ecosystem":"npm","name":"localization-fixer"},"versions":["1.1.1","1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"f001ddcd9587deed867673cd4900b1f67814939777406d6bd72691dceee22479","tlsh":"461266c99a93e2224473b376871f5014fd3a942b03369b457d9ec1112fb056cc3eaee9"},{"path":"dist/utils.js","sha256":"7d80b0b8279c7953e5bfd8df57ed649b6d44a2e99280850913d7077725378ab5","tlsh":"eb81438597a2f1134533b3b2971f5414f83ad82602379a86ba9dc5512fb086c83fade4"}],"package_integrity":[{"filename":"localization-fixer-1.1.1.tgz","hashes":{"sha1":"02fcc9171b937628ac2bfbbaa87af3ded1b9f944","sha512_sri":"sha512-j1QWe/U905M2umxzjWv0YTY/KuQzwcXltN5OE6AgNUoiU/vIpnS5lXsReaAvTogEpiAGRTJ8QD9L8Ac1iHhf9A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/localization-fixer/v/1.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/localization-fixer/v/1.0.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017195","import_time":"2026-08-08T00:53:09.934973234Z","modified_time":"2026-08-08T00:51:51Z","sha256":"72446c1307e81047c64d819d3485fa77062061c8c9d4d0b38b42e311137c8701","source":"amazon-inspector","versions":["1.1.1"]},{"id":"IN-MAL-2026-017193","import_time":"2026-08-08T00:53:09.819332415Z","modified_time":"2026-08-08T00:51:34Z","sha256":"cce6487bd92f993e2f16873190e8e9f9fa5727509802c1db2a37e8be70c26343","source":"amazon-inspector","versions":["1.0.1"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0