目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

base65-77x

MAL-2026-13750
2026-08-11 18:49:32
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in base65-77x (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
5.0.2archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmbase65-77x5.0.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-11T18:49:32Z","published":"2026-08-11T18:49:32Z","schema_version":"1.7.4","id":"MAL-2026-13750","summary":"Malicious code in base65-77x (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ef76e83f2641fcfacf488a6ef61447fac81f6a24cff6287b407a385374b9ddf7)\nThe package impersonates base-x (name, description, keywords, and homepage copied from base-x) and patches the advertised decode() function in both the CommonJS and ESM entrypoints to POST the caller-supplied input string to a hardcoded remote destination at http://46.250.253.63:3000/api/log over plain HTTP before returning the decoded result. Because base-x is commonly used to decode base58/base64 material such as wallet addresses, private keys, seeds, and tokens, any string passed to decode() is silently forwarded to the hardcoded bare-IP endpoint, which is not first-party and not caller-configurable.\n","affected":[{"package":{"ecosystem":"npm","name":"base65-77x"},"versions":["5.0.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/cjs/index.cjs","sha256":"99b4adf8e3995ac7fc8123047a3c1f0b4b8db9c3623117e990a5e451d9e5b6a6","tlsh":"01a1a68e2af611515843b9664a5bf0047378621b662a9f5cfa0fa3107f7052983f6fcf"},{"path":"src/esm/index.js","sha256":"38c43e489c2cca81d6d3972880791ee4b24f96b902e3055803f06cdbca54c522","tlsh":"efa1848e2af610106843b9664a5bf0047378621b662a9f5cfa0fa3107f7152943f6fcf"}],"package_integrity":[{"filename":"base65-77x-5.0.2.tgz","hashes":{"sha1":"0c1e931b86d328a45fde2db8ac68ceeb200c154c","sha512_sri":"sha512-CkF2iwgKoYd4WiuPjWGBp9mTsQRfI6cX5b4zpITq/WqLAyNfWlCjKZDB2AZYhuX8LUQFEqv3sEe1gkpPSawe6A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/base65-77x/v/5.0.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017383","import_time":"2026-08-11T18:52:00.940384124Z","modified_time":"2026-08-11T18:49:32Z","sha256":"ef76e83f2641fcfacf488a6ef61447fac81f6a24cff6287b407a385374b9ddf7","source":"amazon-inspector","versions":["5.0.2"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0