目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@guangnao/agent-proxy

MAL-2026-14047
2026-08-14 19:51:38
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @guangnao/agent-proxy (npm)

凭据/密钥窃取
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
1.2.1archivedVIP 下载
1.4.0unavailable
1.4.2unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npm@guangnao/agent-proxy1.2.1
npm@guangnao/agent-proxy1.4.0
npm@guangnao/agent-proxy1.4.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-14T19:51:38Z","published":"2026-08-14T19:42:12Z","schema_version":"1.7.4","id":"MAL-2026-14047","summary":"Malicious code in @guangnao/agent-proxy (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8da2cb00fa6d2b5a0e5f4a4bdca8ca0cfaedf7e583b0f9e9f54274bcf5c39e06)\nOn invocation of `agent-proxy start`, the CLI opens an outbound WebSocket to an obfuscated author-controlled endpoint (hub.client-llm.com, reconstructed at runtime via XOR+base64 with key 'gnP2p!7xQ' from a base64 blob in dist/cli.js) and accepts remote `job` messages containing arbitrary path and body fields. These are POSTed into the local proxy and forwarded to api.anthropic.com and the Codex/ChatGPT upstream using the installer's on-disk OAuth credentials, with responses streamed back to the hub. An `onlyIfCredentialed` gate ensures only installers with valid Claude/Codex logins are enrolled as worker nodes serving requests originated by the hub operator. The behavior is undocumented; the README states the tool is 'self-use only' and warns that upstream vendor ToS forbid resale or sharing of accounts. The destination URL is not present as a plaintext string, only reconstructed at runtime, concealing it from casual review. The combination provides a remote-controlled command channel (arbitrary request path/body) into the installer's authenticated AI session and silently monetizes the installer's paid subscription for the hub operator's traffic.\n","affected":[{"package":{"ecosystem":"npm","name":"@guangnao/agent-proxy"},"versions":["1.2.1","1.4.2","1.4.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/cli.js","sha256":"d12f5774b17a81a948114de309a2be9e14b646a92ead01983c7b4064b2262a55","tlsh":"9df35b85a27e353b4bed52e1787e0506f3a885a46518802cb32cddef2e6c80455bff79"}],"package_integrity":[{"filename":"agent-proxy-1.2.1.tgz","hashes":{"sha1":"a1458fd5e69edd65487b4af15de227127b2dc321","sha512_sri":"sha512-bzX5N7ZbG+GtbgC2QrIKeA/vGoW/waA9oXOae/NyxS26H8ox9Uw0i+HKqdRokC/XbpG3fSo/Bgwzvd6EbOw+4A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@guangnao/agent-proxy/v/1.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@guangnao/agent-proxy/v/1.4.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@guangnao/agent-proxy/v/1.4.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017923","import_time":"2026-08-14T19:49:49.896567358Z","modified_time":"2026-08-14T19:42:33Z","sha256":"894c7feb1f9f6c277d5eb3d7b5f2de015c2e698cce1663442889221a205aa4a0","source":"amazon-inspector","versions":["1.2.1"]},{"id":"IN-MAL-2026-017921","import_time":"2026-08-14T19:49:49.805257102Z","modified_time":"2026-08-14T19:42:12Z","sha256":"8da2cb00fa6d2b5a0e5f4a4bdca8ca0cfaedf7e583b0f9e9f54274bcf5c39e06","source":"amazon-inspector","versions":["1.4.2"]},{"id":"IN-MAL-2026-017922","import_time":"2026-08-14T19:49:49.840739949Z","modified_time":"2026-08-14T19:42:25Z","sha256":"cd3c0648f70b72257a9302c46ee8abc435015edcedaa560560870b7f0b98b5ed","source":"amazon-inspector","versions":["1.4.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0