MAL-2026-13744Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
374.0.0 | unavailable | — | — | — |
999.0.1 | archived | — | — | VIP 下载 |
| Ecosystem | Package | Version |
|---|---|---|
| npm | @dgn-src-click-to-pay-org/srcdcfreleasecert | 374.0.0 |
| npm | @dgn-src-click-to-pay-org/srcdcfreleasecert | 999.0.1 |
{"schema_version":"1.7.4","id":"MAL-2026-13744","published":"2026-08-11T18:50:11Z","modified":"2026-08-13T22:22:28.091789367Z","summary":"Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2284b9966871244eb99dd61230f6b17e6b2fb315484fb2b3048c51a780820a1f)\nThe package's postinstall script POSTs installer metadata (package name/version, platform, arch, Node version, timestamp) over plain HTTP to a hardcoded sslip.io-wrapped bare IP at http://16-171-38-148.sslip.io:8080/api/install. The scoped name mimics an internal corporate org (@dgn-src-click-to-pay-org) and the version is inflated to 374.0.0, matching the canonical dependency-confusion pattern: a lure package published to the public registry to be resolved by internal build systems that mistakenly reach out for a namespace they expected to be private, with a callback that reports successful installs to an attacker-controlled endpoint. The beacon fires automatically on npm install with no user action, revealing internal build host presence and confirming which corporate targets are vulnerable to further dependency-confusion payloads.\n","affected":[{"package":{"name":"@dgn-src-click-to-pay-org/srcdcfreleasecert","ecosystem":"npm"},"versions":["999.0.1","374.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/check-env.js","sha256":"46c5520d3525e4ab6700a4a5b958685cbe75a5e8f0eabee489179a63f4363e9f","tlsh":"9021b7c855fa9c311f5ae18e60eb590a127d5101351fd8b8b09d00412f93abc52f1fec"},{"path":"package.json","sha256":"d4be85316e5a6e6760644235515328f2adaf1bdf061086e343eb33e942e30625","tlsh":"68f055a8e8154c2324c5aa5b0c2742073620ce4b0651bd0d7b97618c479eb7b8eff16c"}],"package_integrity":[{"filename":"srcdcfreleasecert-999.0.1.tgz","hashes":{"sha1":"b9f988568613e2594d28d633a6cf90f7539cee1d","sha512_sri":"sha512-ltqK87qQfAlxsV8BjMeg0TXcNplNFSlJTEkKW3mk7b20wMmYoKZ+xt3kr3fy3kPoPu9OZYf0peSOMrF/HPMdBw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dgn-src-click-to-pay-org/srcdcfreleasecert/v/999.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dgn-src-click-to-pay-org/srcdcfreleasecert/v/374.0.0"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017386","import_time":"2026-08-11T18:52:01.394906528Z","modified_time":"2026-08-11T18:50:11Z","sha256":"6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d","source":"amazon-inspector","versions":["999.0.1"]},{"id":"IN-MAL-2026-017713","import_time":"2026-08-13T22:20:21.698110377Z","modified_time":"2026-08-13T22:03:33Z","sha256":"2284b9966871244eb99dd61230f6b17e6b2fb315484fb2b3048c51a780820a1f","source":"amazon-inspector","versions":["374.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0