目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@ferudionz/web_logger_js

MAL-2026-14044
2026-08-14 19:03:43
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @ferudionz/web_logger_js (npm)

安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npm@ferudionz/web_logger_js1.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-14T19:03:43Z","published":"2026-08-14T19:03:43Z","schema_version":"1.7.4","id":"MAL-2026-14044","summary":"Malicious code in @ferudionz/web_logger_js (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (42924eef53202ac8b42a142da91ff30445dab53dcf185fa4798efd4d40d1b095)\nThe package ships a single obfuscator.io-style `index.js` with a rotated string array, RC4 key-schedule + XOR string decoder, self-defending anti-debug wrapper, and per-call proxy functions. All identifiers (the `require` target, the HTTP method name, and the destination URL) are reconstructed at runtime from ~130 encoded literals, hiding the actual network destination from static inspection. The sole exported function `connet(x)` unconditionally issues `axios.get(API_BASE_URL + x)` where `API_BASE_URL` is a URL assembled at runtime from ~13 RC4-decoded fragments. Any consumer that calls the package's public API sends its argument to a hardcoded author-controlled destination the caller did not configure. The README hint (`npm install evm_account`) and the name mismatch between the published package and its documented install string are consistent with an EVM/crypto-account-targeted exfiltration helper: a caller passing an account identifier, address, key material, or similar input to `connet()` will silently leak it to the obfuscated endpoint. The concealment of the destination behind RC4 decoding and anti-debug wrapping rules out an inadvertent, documented service call.\n","affected":[{"package":{"ecosystem":"npm","name":"@ferudionz/web_logger_js"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"ae4ad972bd2947f3336256936dd1080991040aa80763033f1e1d5192725f8f7a","tlsh":"7dd2cc9473c1f803228f5b63bf16a9ece52aa8b678c8544be114b89cf4b9407d5b4df0"}],"package_integrity":[{"filename":"web_logger_js-1.0.0.tgz","hashes":{"sha1":"7ac8d2737d3e80cf365e6f62002ee9242c639476","sha512_sri":"sha512-fo9PPTXggc1DHrFA0j0F9Ri2/aGXlsvi3QiKuxXhaXTHmzKRPOsErxgBqRWYGKAtoKpo/vbpCIf3G0OsqupMqA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ferudionz/web_logger_js/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017915","import_time":"2026-08-14T19:24:34.124706517Z","modified_time":"2026-08-14T19:03:43Z","sha256":"42924eef53202ac8b42a142da91ff30445dab53dcf185fa4798efd4d40d1b095","source":"amazon-inspector","versions":["1.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0