目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@ethers-js/contracts

MAL-2026-13937
2026-08-13 17:17:39
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @ethers-js/contracts (npm)

安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@ethers-js/contracts6.9.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-13T17:17:39Z","published":"2026-08-13T17:17:39Z","schema_version":"1.7.4","id":"MAL-2026-13937","summary":"Malicious code in @ethers-js/contracts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (06aee7d1e943a9d9a705acf4f28286eb5460ab9a56057a0811274787478f7c68)\nPackage impersonates the ethers project (real releases publish under `ethers` and `@ethersproject/*`, not `@ethers-js`). The `postinstall` lifecycle script in scripts/postinstall.js is obfuscated with \\x-hex-encoded identifiers (require('fs'), require('https'), spawn('powershell',...)) and a base64-encoded download URL. On Windows, it decodes the URL to https://files.catbox.moe/7vixtr.zip, downloads the archive into %LOCALAPPDATA%\\Microsoft\\<random>, extracts it via PowerShell Expand-Archive, and then invokes a bundled pythonw.exe against r.py with {detached:true, windowsHide:true} and.unref(), executing attacker-controlled code hidden from the user on `npm install`.\n","affected":[{"package":{"ecosystem":"npm","name":"@ethers-js/contracts"},"versions":["6.9.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/postinstall.js","sha256":"b9ee57b2e1f9a47251422232e370a4574c905b1846bf2138d4443dcdd2a843e1","tlsh":"d541f19571e5a22f23dc49e3fa145ef580a79e12b0c5b043836c794e19e914ac7f5cc8"},{"path":"package.json","sha256":"47b177c142ace98e0bc1bd18a09b7a8181efc164df3f3ca9b3f823e317035a2b","tlsh":"def04c11ca118ea32acc5f805819a58ab561ad0788c87c1a33cb456e5b8f77f01ff5dd"}],"package_integrity":[{"filename":"contracts-6.9.0.tgz","hashes":{"sha1":"68c7a69e015cd42c135e4437778d7f77477bea95","sha512_sri":"sha512-rZVtmt5+rTcSWy7te0PIEoVsTN1gtzb32vSn9+4T0dRlbQsvCZsJiL991aqHe2CL+Qv/nPTTQPAQb+0RFewmXQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ethers-js/contracts/v/6.9.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017648","import_time":"2026-08-13T17:24:45.908276614Z","modified_time":"2026-08-13T17:17:39Z","sha256":"06aee7d1e943a9d9a705acf4f28286eb5460ab9a56057a0811274787478f7c68","source":"amazon-inspector","versions":["6.9.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0