目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@ferudionz/webautomation

MAL-2026-14045
2026-08-14 19:03:57
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @ferudionz/webautomation (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.0.0archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npm@ferudionz/webautomation1.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-14T19:03:57Z","published":"2026-08-14T19:03:57Z","schema_version":"1.7.4","id":"MAL-2026-14045","summary":"Malicious code in @ferudionz/webautomation (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a55c1cc52c2e4580b15c1b9e32b436719687f489ee4ee55686aec1ec9a3adc59)\nThe npm package @ferudionz/webautomation exposes a single function connet(x) whose sole behavior is to POST the caller-supplied argument to a hardcoded remote URL. The entire index.js is wrapped in an obfuscator.io-style RC4 string-array (`_0x25ec=[...]`) with a self-defending anti-debug IIFE (`_0x320e22();`) that runs at require time. The destination URL is reconstructed at runtime from ~13 concatenated RC4-decoded fragments, hiding it from static inspection. The package ships no README documenting a legitimate service endpoint, has empty author metadata, and describes itself only as a generic 'logger tool'. The package name and its documented usage suggest the argument passed to connet() is a wallet/account identifier, meaning caller-supplied identifiers are silently exfiltrated to an undisclosed author-controlled destination. The combination of a hidden destination, anti-debug wrapper, and a package that presents itself under an unrelated cover story is inconsistent with legitimate logger/webautomation libraries.\n","affected":[{"package":{"ecosystem":"npm","name":"@ferudionz/webautomation"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"ae4ad972bd2947f3336256936dd1080991040aa80763033f1e1d5192725f8f7a","tlsh":"7dd2cc9473c1f803228f5b63bf16a9ece52aa8b678c8544be114b89cf4b9407d5b4df0"}],"package_integrity":[{"filename":"webautomation-1.0.0.tgz","hashes":{"sha1":"35807f2af5d2567cb178375df3bf1f78e0f09d37","sha512_sri":"sha512-f0F+kR6QqES731ykwzD6UAcK5Kr8uTu/oSzUpxkA+izWmnsQEE1xVMefsKOuq4xIliGKVweblwCfgyb4enPzMA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ferudionz/webautomation/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017916","import_time":"2026-08-14T19:24:34.236206833Z","modified_time":"2026-08-14T19:03:57Z","sha256":"a55c1cc52c2e4580b15c1b9e32b436719687f489ee4ee55686aec1ec9a3adc59","source":"amazon-inspector","versions":["1.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0