目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

harmony-app-toolkit

MAL-2026-14055
2026-08-15 16:10:03
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in harmony-app-toolkit (npm)

安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
22.0.0archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmharmony-app-toolkit21.0.0
npmharmony-app-toolkit22.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-14055","published":"2026-08-15T14:12:26Z","modified":"2026-08-15T16:10:03.318507588Z","summary":"Malicious code in harmony-app-toolkit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (84c12fe64417829f19a3ad302001c909c0825b09e1c4a25c957eb8aa96997f49)\nThe package declares a preinstall lifecycle script (preinstall.js) that reads a hex-encoded command from preinstall.json, decodes it with Buffer.from(hex,'hex'), and passes the result to child_process.exec. The decoded command shells out via curl to https://eousft8gflamm91.m.pipedream.net and POSTs the output of whoami, pwd, hostname, and the contents of /etc/passwd from the installing host. The behavior runs automatically on npm install, uses hex encoding to hide the payload string, and sends installer host identity and a system account file to an attacker-controlled Pipedream endpoint.\n\n## Source: ossf-package-analysis (fff7c26e7d15d67157e1b61e4279a0441a9c09fe5c1ef5ad94a8c5ce1b320156)\nThe OpenSSF Package Analysis project identified 'harmony-app-toolkit' @ 22.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","affected":[{"package":{"name":"harmony-app-toolkit","ecosystem":"npm"},"versions":["22.0.0","21.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"preinstall.js","sha256":"913112caf871d2cd2a23e6becb67ec28401cc294e424d6bf22985c4e1f404bc2","tlsh":"edf07d052dfa1237403b20a54a47580b318ad901313edda2bbee5b516fc5c64cca36c9"}],"package_integrity":[{"filename":"harmony-app-toolkit-21.0.0.tgz","hashes":{"sha1":"ec9061295e4d787f67558c50405788f6efcbf4dd","sha512_sri":"sha512-7ehnUS+iRrWiQGjwHkqljDb25NXYX392sRFvW7+5n3elZh6xztbVDa+MdJUV3FrVcO98QL6usqmd1zZyy6lLAQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/harmony-app-toolkit/v/21.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/harmony-app-toolkit/v/22.0.0"}],"database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-15T14:41:48.071637983Z","modified_time":"2026-08-15T14:12:26Z","sha256":"fff7c26e7d15d67157e1b61e4279a0441a9c09fe5c1ef5ad94a8c5ce1b320156","source":"ossf-package-analysis","versions":["22.0.0"]},{"id":"IN-MAL-2026-017964","import_time":"2026-08-15T16:07:56.951593664Z","modified_time":"2026-08-15T15:58:25Z","sha256":"7a4bf0c3cc6184dfada59b0a31a10acb6afa4784073b71cb19fddd3adf83bd82","source":"amazon-inspector","versions":["21.0.0"]},{"id":"IN-MAL-2026-017963","import_time":"2026-08-15T16:07:56.896176544Z","modified_time":"2026-08-15T15:58:12Z","sha256":"84c12fe64417829f19a3ad302001c909c0825b09e1c4a25c957eb8aa96997f49","source":"amazon-inspector","versions":["22.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0