目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

electro-session

MAL-2026-14242
2026-08-19 04:20:02
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in electro-session (npm)

凭据/密钥窃取安装阶段执行文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmelectro-session0.1.0
npmelectro-session0.1.1
npmelectro-session0.1.3
npmelectro-session0.1.4
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-19T04:20:02Z","published":"2026-08-19T04:03:19Z","schema_version":"1.7.4","id":"MAL-2026-14242","summary":"Malicious code in electro-session (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e7c16137bdd5ac7c97d450fb8ff77103d9c6421f78848b1017f84348c6ec3762)\nelectro-session@0.1.3 presents itself as 'Session utilities' (~170-byte README) but ships ~1MB of heavily obfuscated JavaScript under dist/ (index.js, cli.js, run-once.js, schedule.js), all produced by javascript-obfuscator (listed in devDependencies) using an RC4-encrypted string array, rotating index accessor, and self-defending/debug-protection wrappers that hide every string, module path, URL, and file path. dist/index.js imports node:sqlite, node:fs, node:os, node:path, node:child_process, node:crypto and requires./schedule; package.json pins engines.node to >=22.5.0 (the release that introduced the built-in node:sqlite API) and declares @vercel/blob as a runtime dependency. The combination — built-in SQLite reader + child_process + crypto + a cloud blob upload SDK, wrapped in anti-analysis obfuscation — matches the fingerprint of an infostealer that reads local SQLite-backed credential/session stores (browser Login Data / Cookies / History, wallet extensions, chat app session DBs), decrypts them via child_process-invoked OS primitives, and uploads them via @vercel/blob. dist/schedule.js (imported by index.js) and the sibling dist/run-once.js implement the standard schedule-plus-payload persistence split via node:child_process, consistent with registering a recurring OS task (schtasks/cron/launchctl) that re-invokes run-once.js. There are no npm install lifecycle hooks; the payload is triggered when a developer runs the electro-session bin (dist/cli.js prompts a bilingual y/yes/s/si affirmative — English plus Spanish, indicating targeting of Spanish-speaking developers — then constructs new Sessions({...:true,...:true})), or when any module does require('electro-session') and instantiates Sessions (run-once.js does so unconditionally).\n","affected":[{"package":{"ecosystem":"npm","name":"electro-session"},"versions":["0.1.1","0.1.4","0.1.3","0.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/cli.js","sha256":"9691f92738c66f660de8d5b63e32b8a6563ca2936b36ee40cc13696055c52812","tlsh":"24920f6163d028a0214b8f67771ff5f6e724de9cb5480c8fd0487e54aaa9918efd4e31"},{"path":"dist/index.js","sha256":"80a8a090f8ef7999840cba719da50310ad433d87c307cc0c0a591cd1107f6872","tlsh":"8f15cda063d0e803204f4f637f0abae4ea1daf7d7544588fd5547da85ab9506caf0af0"},{"path":"package.json","sha256":"4c1efeff4c5c376aa794ee023cffb951088c8c7609ef6b21e95a42eaa430694e","tlsh":"f401df20da606d7315c8ae952c7852c2a235894755acbc2832e7420c0f5dabb61fe3ed"}],"package_integrity":[{"filename":"electro-session-0.1.1.tgz","hashes":{"sha1":"e57c703f5f1536101d0e5b8adb2fd5627baa37ee","sha512_sri":"sha512-8+Nly+vY6tnfY5m2Qm/AL1yuveswu8sOe6u6ZouC5dRi1cKc0/GphXEp04qn2vHZ4ZkTXQm3mjkAa85ugsHXZA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/electro-session/v/0.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/electro-session/v/0.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/electro-session/v/0.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/electro-session/v/0.1.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018350","import_time":"2026-08-19T04:18:13.857647532Z","modified_time":"2026-08-19T04:03:19Z","sha256":"0318ee4ebf490cc9933b403626e354c8f811d4e0a17f150a749bec4e82ed81a3","source":"amazon-inspector","versions":["0.1.1"]},{"id":"IN-MAL-2026-018351","import_time":"2026-08-19T04:18:13.893097981Z","modified_time":"2026-08-19T04:03:26Z","sha256":"79385dd62edf04b5afdd3a792aa61144b744a155ec930fbb26a4d60aafa02f55","source":"amazon-inspector","versions":["0.1.4"]},{"id":"IN-MAL-2026-018353","import_time":"2026-08-19T04:18:13.97914218Z","modified_time":"2026-08-19T04:03:44Z","sha256":"e7c16137bdd5ac7c97d450fb8ff77103d9c6421f78848b1017f84348c6ec3762","source":"amazon-inspector","versions":["0.1.3"]},{"id":"IN-MAL-2026-018352","import_time":"2026-08-19T04:18:13.956229062Z","modified_time":"2026-08-19T04:03:36Z","sha256":"6c7367e2b048f3145701058ddf8da2ec1cbe515805b83c3bb85efb11a59174a8","source":"amazon-inspector","versions":["0.1.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0