目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

sw-pluginer

MAL-2026-14211
2026-08-19 02:59:18
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in sw-pluginer (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
82
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmsw-pluginer1.0.0
npmsw-pluginer1.0.1
npmsw-pluginer1.0.2
npmsw-pluginer1.1.0
npmsw-pluginer1.2.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-19T02:59:18Z","published":"2026-08-19T02:49:26Z","schema_version":"1.7.4","id":"MAL-2026-14211","summary":"Malicious code in sw-pluginer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (38427a19b5e267273200d4dc05d0b9a60f0a38bfe7916adaaeb90338af5f1b06)\nsw-pluginer presents itself as a Tailwind plugin for service worker registration, but its main export — invoked when Tailwind processes its config via require('sw-pluginer') — reads a URL from a staged file at node_modules/.bin/manifest.json, performs an HTTP GET to that URL, and passes the response body directly to eval() in the Node build process. The staging file is written by a separate dropper component and is unlinked after being read, hiding the payload destination from static inspection of the sw-pluginer tarball itself. The fetched code is not pinned, hashed, or signature-verified, and it is executed in the developer's Node environment (not in a browser as service worker code) — so whoever controls the staged manifest.json obtains arbitrary code execution on the developer machine at build time. The self-deleting indirection through node_modules/.bin/manifest.json plus eval of unverified network-fetched JavaScript is a covert dropper mechanism, not service worker registration.\n","affected":[{"package":{"ecosystem":"npm","name":"sw-pluginer"},"versions":["1.1.0","1.0.2","1.2.0","1.0.1","1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/register-worker.js","sha256":"ca164ecc2344c5ce1f3ad4e4c75cea4b0fa4c9560f564d59858062d342c93747","tlsh":"b301feaacd81e437057125611806c314e0b7812482239091f3ec93d65ffbc2cd73bcc0"},{"path":"index.js","sha256":"834c8ecadebf0420243421df5d4c24e0dc6cb84fec2c6bbdbea81d99b8cbf657","tlsh":"2b21e4924fdc4997187312905b3b9213e17ec16a6112c2907abf43d53fd302081354fc"}],"package_integrity":[{"filename":"sw-pluginer-1.1.0.tgz","hashes":{"sha1":"930c0a7ce78cca8b8db4bbcef5dd7320a7594d26","sha512_sri":"sha512-MMl1pB9cg2gUGlHc5JJUi5s7Qw78aXNr1R3TocPzjYmY5T0e2lB74N1F5Dd00N3IB3E/o52AIEUGJH58Lz2oow=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sw-pluginer/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018301","import_time":"2026-08-19T02:57:22.208634612Z","modified_time":"2026-08-19T02:49:34Z","sha256":"04cb9419a7170f7f1d55a8515c8d931d0a388fdf9b55c692a72a3f447539b650","source":"amazon-inspector","versions":["1.1.0"]},{"id":"IN-MAL-2026-018300","import_time":"2026-08-19T02:57:22.12018987Z","modified_time":"2026-08-19T02:49:26Z","sha256":"38427a19b5e267273200d4dc05d0b9a60f0a38bfe7916adaaeb90338af5f1b06","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-018304","import_time":"2026-08-19T02:57:22.516514813Z","modified_time":"2026-08-19T02:50:02Z","sha256":"4774f9e54911d1231788224ac0d528431050050cbcc8a053f1f40eb6e73b8ff1","source":"amazon-inspector","versions":["1.2.0"]},{"id":"IN-MAL-2026-018303","import_time":"2026-08-19T02:57:22.424629099Z","modified_time":"2026-08-19T02:49:50Z","sha256":"b5f6a7d297091f57fe43af57f951f3acc3f82e51363747e84b87113c13e76212","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-018302","import_time":"2026-08-19T02:57:22.332600519Z","modified_time":"2026-08-19T02:49:41Z","sha256":"cc3a59d3a151fdca61663452e132622d9f9201013e53a4f57805845c290c5551","source":"amazon-inspector","versions":["1.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0