目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@finaxis/common-js

MAL-2026-14064
2026-08-19 00:23:13
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @finaxis/common-js (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
0.3.4archivedVIP 下载
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npm@finaxis/common-js0.3.10
npm@finaxis/common-js0.3.4
npm@finaxis/common-js0.3.5
npm@finaxis/common-js0.3.6
npm@finaxis/common-js0.3.8
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-14064","published":"2026-08-15T17:07:14Z","modified":"2026-08-19T00:23:13.447815947Z","summary":"Malicious code in @finaxis/common-js (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (832d1ce61ce1f1e1430c60e94175cc80700dfbb2f8d0f46fd7d00b64720026d8)\nPackage publishes under a lodash-imitating identity: keywords `lodash`/`lodash-js`, and the README is a verbatim copy of the official lodash 4.18.1 README. The single shipped file `dist/common-js.js` is not lodash — it is a ~770 KB javascript-obfuscator bundle (17,969-entry rotated string array, `_0xNNNN` identifiers). After deobfuscation the bundle is a browser-based cryptocurrency-mining client: it opens a WebSocket to a caller/config-supplied pool URL, spawns a fan-out of Web Workers keyed by `workerId`, handles `nonce` framing, and bundles an AES-GCM decryption primitive (`aesGcmDecrypt` from @noble/ciphers) for pool message decryption. Wallet and worker identifiers are read from a config object with fallbacks (`cfg.wallet||'x'`, `cfg.worker||'worker'`). A developer who installs this expecting a lodash-family utility and ships it in a web application will silently mine cryptocurrency on their end users' browsers, consuming visitor CPU/battery and creating a compliance/abuse liability for the downstream site. The identity masquerade (name/keywords/README all mimicking lodash) combined with heavy string-array obfuscation of the real payload is the standard shape of a supply-chain masquerade attack.\n","affected":[{"package":{"name":"@finaxis/common-js","ecosystem":"npm"},"versions":["0.3.4","0.3.6","0.3.10","0.3.8","0.3.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/common-js.js","sha256":"54983b10ced567632cf51c2b732a034924ef73ec11140cc7a2c2a1a5fbe43030","tlsh":"a604f76562d0b99c13471fb63b2fb0d9dc2d199bb8884b9fe244fc84b5a5317e6d8830"},{"path":"package.json","sha256":"ee813ff10e4cddafd9a8ed9619c26b5e226e3de51dea7ae7bf679d9ea3638165","tlsh":"d3119e35ccb45e531bd868d60878e152ad2c4e5b9588bd0433d6b04d4a5cabb11fe15c"}],"package_integrity":[{"filename":"common-js-0.3.4.tgz","hashes":{"sha1":"27376920a17cb4b1e3a61628876658673ad4b98a","sha512_sri":"sha512-coSm5CXVwsqf9p4bYeft02D4VWzET4Qf+E5vpsWLe+48HfGFoAay1hcSBoeya6HnAXZPSai7ZDhbAhLN2k3kFQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@finaxis/common-js/v/0.3.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@finaxis/common-js/v/0.3.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@finaxis/common-js/v/0.3.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@finaxis/common-js/v/0.3.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@finaxis/common-js/v/0.3.5"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017968","import_time":"2026-08-15T17:08:59.179122132Z","modified_time":"2026-08-15T17:07:14Z","sha256":"f708a31239d3dc7490906a4a41f5ccb3cb76c99f89bc87b5ad5884939bb2d308","source":"amazon-inspector","versions":["0.3.4"]},{"id":"IN-MAL-2026-018266","import_time":"2026-08-19T00:21:14.770348651Z","modified_time":"2026-08-19T00:06:31Z","sha256":"d3a81522907c6036250cd04caf2b6350ad1903fd50ed138cda550ec33a1a7ea0","source":"amazon-inspector","versions":["0.3.6"]},{"id":"IN-MAL-2026-018268","import_time":"2026-08-19T00:21:14.953987143Z","modified_time":"2026-08-19T00:06:46Z","sha256":"832d1ce61ce1f1e1430c60e94175cc80700dfbb2f8d0f46fd7d00b64720026d8","source":"amazon-inspector","versions":["0.3.10"]},{"id":"IN-MAL-2026-018267","import_time":"2026-08-19T00:21:14.876006876Z","modified_time":"2026-08-19T00:06:38Z","sha256":"858e186e40af34fa05e49209b9bfeb758f4b734da30dacd6bd66cdb5c77a368b","source":"amazon-inspector","versions":["0.3.8"]},{"id":"IN-MAL-2026-018265","import_time":"2026-08-19T00:21:14.695226308Z","modified_time":"2026-08-19T00:06:23Z","sha256":"c6fdee952074aa29c57bde30ce12f536868aba1a38faf68a861d856e21cd7f36","source":"amazon-inspector","versions":["0.3.5"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0