目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

chai-jsonss

MAL-2026-13692
2026-08-10 11:56:07
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in chai-jsonss (npm)

凭据/密钥窃取
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
156
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmchai-jsonss3.7.7
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-10T11:56:07Z","published":"2026-08-10T11:56:07Z","schema_version":"1.7.4","id":"MAL-2026-13692","summary":"Malicious code in chai-jsonss (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3b1fff32102bc74783cae571646ec0fd68b14c614b35a63badd814a64caa3b67)\nOn import, index.js invokes postCallers() which resolves a base64-encoded URL stored in lib/const.js (decoding to https://1uznbx.s.gy/7xdQmt), GETs the response via axios, base64-decodes response.data.model, and passes it to new Function(require) — executing attacker-controlled JavaScript in-process. The destination is hidden as a DEV_API_KEY field on a fake process.env-shaped local module, and the payload URL is a shortlink to a mutable remote resource. The package name resembles chai but its main entry contains no chai-related functionality; the only import-time behavior is fetch-and-eval of remote code.\n","affected":[{"package":{"ecosystem":"npm","name":"chai-jsonss"},"versions":["3.7.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/caller.js","sha256":"2db9b5dcbfbcf4fdf6c46042e0d5ea14324f29e0081fa8edd31d48c889e5baa2","tlsh":"bbe0205f25f8205c157311ccb51688076187d0327141c0f275ec51961fc0f692291bd1"},{"path":"lib/const.js","sha256":"f5940f8a2526599a6132503df100f8d3073b91b8aed775402a8542387c1d8089","tlsh":"49c08cc35094ac965071a233b24daa21f187d34f0c8100013ef0b8840a3a7ba3c84eab"}],"package_integrity":[{"filename":"chai-jsonss-3.7.7.tgz","hashes":{"sha1":"bf71a5b5274da00ab65c28e360f3c4420a4e0482","sha512_sri":"sha512-DAnOczn/xIDDL5bqA4yFYpE9hx/QWxsoy+/ukXmRpl9Hbpvo7bnVo+t5zIKnn+H2mseBbmVkLWHk/5JjY5aKTQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chai-jsonss/v/3.7.7"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017246","import_time":"2026-08-10T12:24:46.199172734Z","modified_time":"2026-08-10T11:56:07Z","sha256":"3b1fff32102bc74783cae571646ec0fd68b14c614b35a63badd814a64caa3b67","source":"amazon-inspector","versions":["3.7.7"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0