MAL-2026-13738Malicious code in @openzeppelin-5/contracts (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
1.0.0 | archived | — | — | VIP 下载 |
1.0.1 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| npm | @openzeppelin-5/contracts | 1.0.0 |
| npm | @openzeppelin-5/contracts | 1.0.1 |
{"modified":"2026-08-12T06:00:00Z","published":"2026-08-11T15:16:36Z","schema_version":"1.7.4","id":"MAL-2026-13738","summary":"Malicious code in @openzeppelin-5/contracts (npm)","details":"@openzeppelin-5/contracts is a malicious npm package published by npm account `mssjeep843` that impersonates OpenZeppelin's `@openzeppelin/contracts` (the v5 line) via the look-alike scope `@openzeppelin-5`, falsely describing itself as a \"compatibility distribution\". It ships no Solidity contracts — only an install-time payload (index.js) run via preinstall/postinstall that harvests credential-shaped environment variables and reads and exfiltrates SSH private keys, cloud credentials (AWS/GCP/Kubernetes/Docker), Solana/Anchor/NEAR/Sui wallet keys, Foundry keystores, `.git-credentials` and local `.env` files to `https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09`. It is one of a series of DeFi/crypto impersonation packages from the same account sharing this webhook.site endpoint, which also squat Aerodrome Finance, Camelot AMM, Euler EVC, BoringVault and Uniswap Permit2.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (800da818da3fee0353766227eafcd43c0c7cf7fd0126af5ded48b7c1ba522e21)\nPackage name typosquats @openzeppelin/contracts. package.json declares both preinstall and postinstall as `node index.js || true`, so the payload auto-executes on `npm install`. index.js harvests process.env entries matching KEY|TOKEN|SECRET|MNEMONIC|WALLET|AWS|GITHUB|NPM and reads installer-side credential files including ~/.aws/credentials, ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.kube/config, ~/.docker/config.json, ~/.netrc, ~/.npmrc, ~/.git-credentials, gcloud/solana/sui/foundry keystores, and local.env files. The bundle is POSTed to a hardcoded webhook.site endpoint (path 326b0891-2093-4800-a4c1-686ce3e07b09) via a detached child process spawned with a randomized 60–240 second delay to outlive install-time scanning windows. A hostname regex (/^(scan-|detonation|sandbox|ubuntu-fc-uvm)/i) throws early on known sandbox/scanner hosts as anti-analysis gating.\n","affected":[{"package":{"ecosystem":"npm","name":"@openzeppelin-5/contracts"},"versions":["1.0.0","1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"7ecd1b4ed15e168b5ce7317ddd4b9cde6ffc513b9175269ff12a5eb64a4f7b85","tlsh":"725163a322fa65982563e2d2e6576120623bf3827546f8c4f29c24144fce438c9f36fd"}],"package_integrity":[{"filename":"contracts-1.0.0.tgz","hashes":{"sha1":"b8de8e11950b86a5c24a3c77c388c0ffcc6d584a","sha512_sri":"sha512-87+P/Ap128NGKlPLIdximS72WIRGOWlHq9lYiVm42muISamlpEJ+cdXtT4p0E4xcS0Gk/8v7lGRIiWi3BpxHSA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openzeppelin-5/contracts/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openzeppelin-5/contracts/v/1.0.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]},{"name":"SafeDep","type":"FINDER","contact":["https://safedep.io"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017360","import_time":"2026-08-11T15:26:48.389466352Z","modified_time":"2026-08-11T15:16:36Z","sha256":"078ff524fafdb7c803081834abe8cf4678931b6f735fc695c8ef1ad339748e8f","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-017362","import_time":"2026-08-11T15:26:48.619801415Z","modified_time":"2026-08-11T15:16:56Z","sha256":"800da818da3fee0353766227eafcd43c0c7cf7fd0126af5ded48b7c1ba522e21","source":"amazon-inspector","versions":["1.0.1"]}],"iocs":{"urls":["https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09"]}}}数据来源:OpenSSF Malicious Packages · Apache-2.0