MAL-2026-13737Malicious code in @openzeppelin-4/contracts (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
1.0.0 | unavailable | — | — | — |
1.0.1 | archived | — | — | VIP 下载 |
| Ecosystem | Package | Version |
|---|---|---|
| npm | @openzeppelin-4/contracts | 1.0.0 |
| npm | @openzeppelin-4/contracts | 1.0.1 |
{"modified":"2026-08-12T06:00:00Z","published":"2026-08-11T15:16:48Z","schema_version":"1.7.4","id":"MAL-2026-13737","summary":"Malicious code in @openzeppelin-4/contracts (npm)","details":"@openzeppelin-4/contracts is a malicious npm package published by npm account `mssjeep843` that impersonates OpenZeppelin's `@openzeppelin/contracts` (the v4 line) via the look-alike scope `@openzeppelin-4`, falsely describing itself as a \"compatibility distribution\". It ships no Solidity contracts — only an install-time payload (index.js) run via preinstall/postinstall that harvests credential-shaped environment variables and reads and exfiltrates SSH private keys, cloud credentials (AWS/GCP/Kubernetes/Docker), Solana/Anchor/NEAR/Sui wallet keys, Foundry keystores, `.git-credentials` and local `.env` files to `https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09`. It is one of a series of DeFi/crypto impersonation packages from the same account sharing this webhook.site endpoint, which also squat Aerodrome Finance, Camelot AMM, Euler EVC, BoringVault and Uniswap Permit2.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2841eb854dad391b8cf3d290704a888d5ac186a1f51aec84594eaa09acdfeb68)\nPackage name @openzeppelin-4/contracts impersonates the @openzeppelin/contracts scope but ships no Solidity contracts — only index.js, executed via lifecycle scripts. index.js enumerates process.env for credential-shaped keys (KEY, TOKEN, SECRET, AWS, GITHUB, NPM, MNEMONIC, WALLET, INFURA, etc.), reads installer secret files including ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.kube/config, ~/.docker/config.json, ~/.netrc, ~/.npmrc, ~/.gitconfig, ~/.git-credentials, gcloud application default credentials, Solana/Anchor/Sui keys, Foundry keystores, and project.env files, then POSTs the collected data to https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09. Delivery uses spawn(process.execPath, ['-e', src], { detached: true, stdio: 'ignore' }) with a randomized 60–240 second delay, and the script bails out when the hostname or username matches sandbox/scanner patterns (scan-, detonation, sandbox, ubuntu-fc-uvm) or when canary env markers are present, evading install-time analysis.\n","affected":[{"package":{"ecosystem":"npm","name":"@openzeppelin-4/contracts"},"versions":["1.0.1","1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"b7d297845b21b9e50cb6b4229f60adbd7af572f1c8038b56db8213be1436fd13","tlsh":"9451b683a2fe55a9126393e5e6236235823bf240b016d4e4f3ac54415fdb164c9b35fc"},{"path":"package.json","sha256":"40792c0d6846ac1e32a7cc51bf22be727b2cc4b5c9afc16221226b26c4da2468","tlsh":"e8e026300d52a33321e00ad6257bc85da0a6aa1a51883c0553c361ce82edb7284ff60e"}],"package_integrity":[{"filename":"contracts-1.0.1.tgz","hashes":{"sha1":"0d49caf08b7ed3f15b70426b187a7647c403e4d8","sha512_sri":"sha512-xdFmvYYbmuGfHKfOq/nSSHuYT5vjUv5pNFESA2qvIam+k0e1zJbnw1+NR35TZvcA6vMlhK4MLhK464uj09Cf8A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openzeppelin-4/contracts/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openzeppelin-4/contracts/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]},{"name":"SafeDep","type":"FINDER","contact":["https://safedep.io"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017361","import_time":"2026-08-11T15:26:48.469062997Z","modified_time":"2026-08-11T15:16:48Z","sha256":"2841eb854dad391b8cf3d290704a888d5ac186a1f51aec84594eaa09acdfeb68","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017364","import_time":"2026-08-11T15:26:48.833021928Z","modified_time":"2026-08-11T15:17:15Z","sha256":"af69458eaa45c49ecd88e7c778bb02f44871683f400ae81b9e5640e8c1710842","source":"amazon-inspector","versions":["1.0.0"]}],"iocs":{"urls":["https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09"]}}}数据来源:OpenSSF Malicious Packages · Apache-2.0