目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

lodsh-cli

MAL-2026-14184
2026-08-18 23:59:48
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in lodsh-cli (npm)

安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmlodsh-cli1.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-18T23:59:48Z","published":"2026-08-18T23:59:48Z","schema_version":"1.7.4","id":"MAL-2026-14184","summary":"Malicious code in lodsh-cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2803016f5b10510cdb31304197a1670396290e9be96fe647fd6c505d1f487273)\nlodsh-cli is a typosquat of lodash-cli. Its scripts/postinstall.js runs automatically on npm install and performs two hostile actions. First, it XOR-decodes a hardcoded URL (key 'stf2026') stored as an integer array, downloads a Windows executable to %TEMP%/main.exe (and on WSL runs a decoded PowerShell/cmd bridge command), and spawns the binary detached — arbitrary remote code execution on the installer's machine. Second, it POSTs platform information to a hardcoded bare IP 193.70.34.101:20099/vote, with the host assembled from a string-split array to hide the literal, serving as an install beacon and target selector. URLs, launcher commands, and script fragments are stored as XOR-encoded byte arrays and decoded at runtime to evade static inspection.\n","affected":[{"package":{"ecosystem":"npm","name":"lodsh-cli"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/postinstall.js","sha256":"dbf71345b53850ffcdabfb93ab845bf80709a74331492b4d1d031062feeb95d0","tlsh":"47d13fca1ef59035874bf96884cf9d13b2a6c207320e4a65ff8f42107f5793c85a69e9"}],"package_integrity":[{"filename":"lodsh-cli-1.0.0.tgz","hashes":{"sha1":"96c7534fc1bb52b3a429531514a57ffed9de6430","sha512_sri":"sha512-n20UI9x56TMN3L6l2HzH8T2xN+s0snMieBn9wQV3Qwlp6cLRDqHZ2E40kLYaJzQzqh3Ts3CmrbFv79/KWX83Rw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/lodsh-cli/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018254","import_time":"2026-08-19T00:21:13.528453648Z","modified_time":"2026-08-18T23:59:48Z","sha256":"2803016f5b10510cdb31304197a1670396290e9be96fe647fd6c505d1f487273","source":"amazon-inspector","versions":["1.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0