目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

fast-glob-fast

MAL-2026-14177
2026-08-19 02:59:14
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in fast-glob-fast (npm)

凭据/密钥窃取远程访问后门安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmfast-glob-fast0.2.0
npmfast-glob-fast10.0.0
npmfast-glob-fast11.0.0
npmfast-glob-fast4.0.1
npmfast-glob-fast8.0.0
npmfast-glob-fast9.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"schema_version":"1.7.4","id":"MAL-2026-14177","published":"2026-08-18T23:49:26Z","modified":"2026-08-19T02:59:14.258628928Z","summary":"Malicious code in fast-glob-fast (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7695ac02a2492bbf3118fc68514378edb201a93183f2dcb0035727781f31d408)\nfast-glob-fast is a name-squat of the popular fast-glob package (its repository field even points at mrmlnc/fast-glob). The declared postinstall hook `node scripts/postinstall-test.mjs` computes the installer's `~/.ssh/authorized_keys` path per-platform (darwin/linux/win32), creates `~/.ssh` at mode 0700 if missing, and appends to `authorized_keys` at mode 0600 via `appendFileSync`. The same script defines a top-level constant `DEFAULT_TEXT = 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5... dkhrustalev'` — a staged attacker ed25519 public key. Appending any key line to authorized_keys grants passwordless SSH login as the installing user; even though the current build only appends comment lines, the primitive, the target file, and the embedded attacker key together form a persistence/remote-access dropper wired to run automatically on `npm install`. The same postinstall additionally collects `username`, `hostname`, non-internal MAC address, `platform`, and `arch`, and POSTs them as a JSON `systemInfo` event (optionally with a bearer token) to a URL taken from `FAST_GLOB_FAST_EVENT_URL`, reporting the outcome of the authorized_keys write — a reporting channel co-located with the backdoor primitive.\n","affected":[{"package":{"name":"fast-glob-fast","ecosystem":"npm"},"versions":["11.0.0","9.0.0","4.0.1","10.0.0","0.2.0","8.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/postinstall-test.mjs","sha256":"9b6d962d0b1b1dde0044b95afa6746dde1db88d71f5cb69781dcec744c73e032","tlsh":"b0a1961563f016305b6a217e064a10337275e013261e9cacb2ddcb547f972a99e73aed"},{"path":"package.json","sha256":"61a395ffc1383da0f936a9ced3b1020437dd5071fc0446c66c6a44e157e990ca","tlsh":"1c617856dc69cdf309c36166bcb80ab1b62028531f99f80e7326527d0b2e82f10bc97d"}],"package_integrity":[{"filename":"fast-glob-fast-11.0.0.tgz","hashes":{"sha1":"b1e8141a54f1b99b6fb679d921c0420fddfd1c23","sha512_sri":"sha512-WMxM8oNgJxspcdaJCvKKcUtbyKu3/1kD2r4FRYfBPNAxQ/136rFsgYQWePJn943DGHO79pe0WNvjoUCSlhGjVg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fast-glob-fast/v/11.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fast-glob-fast/v/9.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fast-glob-fast/v/4.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fast-glob-fast/v/10.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fast-glob-fast/v/0.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fast-glob-fast/v/8.0.0"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018231","import_time":"2026-08-19T00:21:11.232866091Z","modified_time":"2026-08-18T23:56:21Z","sha256":"06e1d99a3a1c42a611ef74cf3716f3caad1df91ace6c19d448daaa140f8e5c1c","source":"amazon-inspector","versions":["11.0.0"]},{"id":"IN-MAL-2026-018226","import_time":"2026-08-19T00:21:10.746130191Z","modified_time":"2026-08-18T23:49:26Z","sha256":"92ced9e788505da600a8b79bef3678101e5a0480e6b8ddb754e9472c8a63cf63","source":"amazon-inspector","versions":["9.0.0"]},{"id":"IN-MAL-2026-018298","import_time":"2026-08-19T02:57:21.941471119Z","modified_time":"2026-08-19T02:44:05Z","sha256":"d0b15e32c14394ed90eb53c8e33652c9e1be44bb3aa29a1e0341831f2a07996e","source":"amazon-inspector","versions":["4.0.1"]},{"id":"IN-MAL-2026-018296","import_time":"2026-08-19T02:57:21.687355122Z","modified_time":"2026-08-19T02:43:47Z","sha256":"f30cb2af0de95b99ad26614e9e2ac080aabcabc45db443b106cb5127c500ef10","source":"amazon-inspector","versions":["10.0.0"]},{"id":"IN-MAL-2026-018297","import_time":"2026-08-19T02:57:21.82782249Z","modified_time":"2026-08-19T02:43:54Z","sha256":"7695ac02a2492bbf3118fc68514378edb201a93183f2dcb0035727781f31d408","source":"amazon-inspector","versions":["0.2.0"]},{"id":"IN-MAL-2026-018295","import_time":"2026-08-19T02:57:21.548558494Z","modified_time":"2026-08-19T02:43:36Z","sha256":"81597420047bbddb80acd01006ebf15f9cb637c95e6b9232f79f23fde6689388","source":"amazon-inspector","versions":["8.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}

数据来源:OpenSSF Malicious Packages · Apache-2.0