目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

chaikit

MAL-2026-14201
2026-08-19 01:59:26
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in chaikit (npm)

文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
55
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmchaikit2.3.5
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-19T01:59:26Z","published":"2026-08-19T01:59:26Z","schema_version":"1.7.4","id":"MAL-2026-14201","summary":"Malicious code in chaikit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a4711ba83393e8da11ab4368f9b38dac3de00bc523946cc27e4e47f38a51b9c4)\nThe package's main entry (index.js) unconditionally requires./lib/config, a ~4MB obfuscator.io-style file (RC4 string-array decoder with ~23,902 entries, hex-encoded property names) whose top-level IIFE self-executes on load. Any consumer that imports chaikit runs this opaque code in their process. The advertised middleware in index.js is a trivial next() passthrough, so the obfuscated blob is the only substantive behavior of the package. package.json bundles axios as a runtime dependency, giving the opaque code a network egress channel. The README impersonates the pino logger (pino badges, pinojs/pino links, chai/chai-kit usage snippet), while the package.json description is unrelated boilerplate ('management of vulnerabilities') and file.js references a nonexistent./pino module — cover-story metadata consistent with a package published to be resolved by developers searching for chai or pino tooling. The combination of import-time execution of a large opaque blob, a mismatched cover story, and a bundled HTTP client is the canonical loader shape of an installer-harm supply-chain payload.\n","affected":[{"package":{"ecosystem":"npm","name":"chaikit"},"versions":["2.3.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/config.js","sha256":"88d8da1b1148a07973cd1ec96d1f67d4f672b83635ec342783c1df6e38a4ad0c","tlsh":"e81674cc6688e423c1cc2b93be0539abf17a686294c8a167df557d5db8bc40bc1a4fd4"},{"path":"index.js","sha256":"4e6c4e61a7019ab0affe9c2d20e36701b330ec357be205930355bac1464f9316","tlsh":"0421149124d560ce9938dac0f6306115acdbc677260752b3bdfc97c927860080161fba"},{"path":"package.json","sha256":"6cea40708f1d8e795b580d4f171644e15cd1ce21594cb7dc05189030b0ec8e75","tlsh":"b6017b20da784e2301ed25524c2a06437a654c575528fc2932db512d0f9d5fb05bf21d"}],"package_integrity":[{"filename":"chaikit-2.3.5.tgz","hashes":{"sha1":"b6114010391367e1ef7edb2fd031f3ee67e4b58e","sha512_sri":"sha512-gN+9azR+KKHGISKTJD2gYZEf28tubkMgeH/2UKVUcnVxWQzVp11hC/uZEPFICdBsTJJpsnY9i1yRweEZrUhbEg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/chaikit/v/2.3.5"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018287","import_time":"2026-08-19T02:31:08.434609818Z","modified_time":"2026-08-19T01:59:26Z","sha256":"a4711ba83393e8da11ab4368f9b38dac3de00bc523946cc27e4e47f38a51b9c4","source":"amazon-inspector","versions":["2.3.5"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0