MAL-2026-14255Malicious code in secp256k1-lib (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
1.0.0 | archived | — | — | VIP 下载 |
1.0.1 | unavailable | — | — | — |
1.0.2 | unavailable | — | — | — |
1.0.3 | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| npm | secp256k1-lib | 1.0.0 |
| npm | secp256k1-lib | 1.0.1 |
| npm | secp256k1-lib | 1.0.2 |
| npm | secp256k1-lib | 1.0.3 |
{"modified":"2026-08-19T04:49:46Z","published":"2026-08-19T04:43:49Z","schema_version":"1.7.4","id":"MAL-2026-14255","summary":"Malicious code in secp256k1-lib (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dd45f2520f57a18e182ea26170f8d6d3b4296929c66dbbf2ea0eb632adb1f46a)\nPackage name mimics the widely used `secp256k1` cryptography library but contains no cryptographic functionality. The declared `main` (`index.js`) is a single 33KB obfuscator.io-packed bundle whose only readable tokens are `require(` and `axios`; all strings — including target hostnames, URLs, and function names — are hex-escaped entries in the `_0x4058` string array that are reconstructed at runtime. README is 24 bytes and the package description (`logger tool for validation entry`) does not match a secp256k1 implementation. On `require('secp256k1-lib')` the obfuscated bundle executes and instantiates an HTTP client (axios) targeting a runtime-constructed destination that could not be recovered from the shipped bytes. Shape matches a credential/wallet-stealer loader: name confusion with a high-value crypto package + no legitimate functionality + obfuscated import-time network capability with a hidden destination.\n","affected":[{"package":{"ecosystem":"npm","name":"secp256k1-lib"},"versions":["1.0.0","1.0.2","1.0.1","1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"ae4ad972bd2947f3336256936dd1080991040aa80763033f1e1d5192725f8f7a","tlsh":"7dd2cc9473c1f803228f5b63bf16a9ece52aa8b678c8544be114b89cf4b9407d5b4df0"}],"package_integrity":[{"filename":"secp256k1-lib-1.0.0.tgz","hashes":{"sha1":"087448f1583621d8cb5a238a89bca1591ffad338","sha512_sri":"sha512-ga9huZ1QdIaQU9vQk7hX7fy/9iu8eq+KCkKeirW0D242ca3wyxRF5SP21OTH4UGYOS0h3BkyTaHrWORftdR0Tg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/secp256k1-lib/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/secp256k1-lib/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/secp256k1-lib/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/secp256k1-lib/v/1.0.3"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018366","import_time":"2026-08-19T04:47:47.768617582Z","modified_time":"2026-08-19T04:44:13Z","sha256":"17719ed10229a405c54b60369c8c567a5964f6613aec21ead50e0d4eccb37104","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-018363","import_time":"2026-08-19T04:47:47.400193958Z","modified_time":"2026-08-19T04:43:49Z","sha256":"57d7b119d3510a8e00d57da8b51c023a77f4133008a24fed5e4644d4cf5d353e","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-018364","import_time":"2026-08-19T04:47:47.507225307Z","modified_time":"2026-08-19T04:43:57Z","sha256":"8e9ffe9aa6410c78f18aa4a432419b77539b2bb1fc893896ae00f3cc22f6d26d","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-018365","import_time":"2026-08-19T04:47:47.603999433Z","modified_time":"2026-08-19T04:44:06Z","sha256":"dd45f2520f57a18e182ea26170f8d6d3b4296929c66dbbf2ea0eb632adb1f46a","source":"amazon-inspector","versions":["1.0.3"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0