目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@opezneppelin/contracts

MAL-2026-13940
2026-08-13 17:17:31
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @opezneppelin/contracts (npm)

安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@opezneppelin/contracts5.0.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-13T17:17:31Z","published":"2026-08-13T17:17:31Z","schema_version":"1.7.4","id":"MAL-2026-13940","summary":"Malicious code in @opezneppelin/contracts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (abe04ec28ed56cb0a253131129df8078d425f8a0c579c439ced9c75b6977a6ab)\n@opezneppelin/contracts is a typosquat of @openzeppelin/contracts. Its postinstall lifecycle script (scripts/postinstall.js) hex-escapes all module names, method names, and string constants (fs, https, child_process, powershell, -NoP,.exe) and stores the download URL as a base64 literal that decodes to https://files.catbox.moe/9bppy2.zip. On Windows installers, the script downloads that ZIP to %TEMP%, expands it via PowerShell Expand-Archive, recursively searches the extracted contents for the first.exe, and spawns it detached. The destination is an anonymous, mutable file-host (catbox.moe) unrelated to any OpenZeppelin infrastructure, and the fetched executable is opaque attacker-controlled content. The behavior fires automatically on npm install without any user action, resulting in arbitrary code execution on the installer's Windows host.\n","affected":[{"package":{"ecosystem":"npm","name":"@opezneppelin/contracts"},"versions":["5.0.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/postinstall.js","sha256":"be0e358b5b4533c985c53d576f99a13ea680a03cda0d0885c50d062e540a043c","tlsh":"cc41eed571d9632b23ec44e7f6245ee581a7dd12b1c9b043831c7a4e14d908acae6dc9"}],"package_integrity":[{"filename":"contracts-5.0.2.tgz","hashes":{"sha1":"4b518ff7f9bf8c5e8fbbadf5413b9d2891411145","sha512_sri":"sha512-Dj5/ri6BPZ2ZHeI2npsZalMnmZOzdytcK0/XEDf+C4Ci0lIK+PXQIEY/gy+8eaj2SNQZYdXFAjDTgIt8HPW+wg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@opezneppelin/contracts/v/5.0.2"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017647","import_time":"2026-08-13T17:24:45.875181164Z","modified_time":"2026-08-13T17:17:31Z","sha256":"abe04ec28ed56cb0a253131129df8078d425f8a0c579c439ced9c75b6977a6ab","source":"amazon-inspector","versions":["5.0.2"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0