目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

env-local

MAL-2026-13694
2026-08-11 15:28:30
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in env-local (npm)

凭据/密钥窃取文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
18.4.2archivedVIP 下载
18.4.3unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmenv-local18.4.2
npmenv-local18.4.3
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-13694","published":"2026-08-10T11:53:57Z","modified":"2026-08-11T15:28:30.046649414Z","summary":"Malicious code in env-local (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7faefbcd9110b5e08b469d72d6541875ba4e2702c4490d1a24c37b313160f86b)\nenv-local presents itself as a dotenv-compatible.env loader (README, keywords, and API mirror motdotla/dotenv), but lib/main.js unconditionally requires lib/tui-options.js, which activates a full-host spyware payload on module load. tui-options.js captures the desktop every 3 seconds (screenshot-desktop+sharp on Windows, screencapture on macOS) and POSTs the JPEG bytes to http://192.99.204.157:5000/upload with X-Computer-Name, X-Platform, and X-Resolution headers identifying the host. In parallel, a 1-second interval polls http://192.99.204.157:5000/get_buffer and replays the returned mouse-click coordinates and keystrokes on the installer's desktop via @nut-tree-fork/nut-js, giving the operator of that endpoint interactive remote control of the machine. On Windows, the module writes %APPDATA%\\ScreenCaptureClient\\launch-screen-client.vbs and registers HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\ScreenCaptureClient via reg.exe to invoke the launcher with wscript.exe at every user logon, persisting the spyware and remote-input agent beyond the Node process.\n","affected":[{"package":{"name":"env-local","ecosystem":"npm"},"versions":["18.4.2","18.4.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/tui-options.js","sha256":"cc313e41108b632ed8b4ea6dc8e0a12e25f3ed905827cee4e6c39d1b291b8a4b","tlsh":"3cf183dd583754208b72bba79a67450ff63693173401c289babc82942f77568c722edc"},{"path":"lib/main.js","sha256":"c956a80948f211ad6f104ec7432e960766b8f9e1f137e8dd8f9b181313b38a21","tlsh":"15327204a9f9761107c3b2d2954f5009a9bac227361c9f907a8cb3d86f49e78c5e37dd"}],"package_integrity":[{"filename":"env-local-18.4.2.tgz","hashes":{"sha1":"33a45ecb9bf7f04b11bbb53bc71b66ad84ae0967","sha512_sri":"sha512-/c2tzUB/ydwq5qj7PRqMDHraDGLXpJCWKnCk028D5otKE9OlGQJxYt2Ik5Avy90IerW3dusG9sy8sVCrc5TEdw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/env-local/v/18.4.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/env-local/v/18.4.3"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017231","import_time":"2026-08-10T12:24:44.501268016Z","modified_time":"2026-08-10T11:53:57Z","sha256":"ac368f7cba943b89781656da7f45ac393cf8b105eaa54a29c42a78622a2fde0b","source":"amazon-inspector","versions":["18.4.2"]},{"id":"IN-MAL-2026-017355","import_time":"2026-08-11T15:26:47.899393077Z","modified_time":"2026-08-11T15:14:31Z","sha256":"7faefbcd9110b5e08b469d72d6541875ba4e2702c4490d1a24c37b313160f86b","source":"amazon-inspector","versions":["18.4.3"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0