目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

ranux-dev

MAL-2026-14259
2026-08-19 04:59:57
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in ranux-dev (npm)

凭据/密钥窃取
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
141
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
永久样本归档NAS
版本状态大小SHA-256获取方式
5.0.0unavailable
样本保存在内网 NAS 隔离区,不公开镜像地址;已开通会员可直接从平台下载。同步任务不会解压或执行样本。
受影响版本
EcosystemPackageVersion
npmranux-dev5.0.0
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-19T04:59:57Z","published":"2026-08-19T04:59:57Z","schema_version":"1.7.4","id":"MAL-2026-14259","summary":"Malicious code in ranux-dev (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4dde928a7de2064f13b18847a56607605bd33f1331a57bb0be0ccf585fa5d86f)\npackage.json declares the dependency `@whiskeysockets/baileys` but resolves it from `github:rcedubot/X` instead of the npm registry. Installing ranux-dev pulls arbitrary, unpinned, mutable code from that personal GitHub account under the name of a widely-used WhatsApp Web library, and that code runs in the installer's Node process with full WhatsApp session and credential access. Every shipped source file (index.js, config.js, database.js, tenantManager.js, command.js, lib/*.js, plugins/*.js) is heavily obfuscated with obfuscator.io-style transforms and an RC4-over-base64 string decoder, so endpoints, credentials, and control flow cannot be reviewed statically. config.js exports a frozen `SECRETS` object with hardcoded encrypted strings alongside `API_ENDPOINTS` and `NETWORK_CONFIG` (MongoDB-shaped) constants. The combination — dependency substitution of a popular WhatsApp library from an unaffiliated GitHub account, uniform obfuscation across the tarball, a multi-tenant WhatsApp/MongoDB architecture, and shipped hardcoded credential-shaped constants — matches the session-harvester pattern in which installer WhatsApp sessions and tenant data are funneled to an author-controlled backend.\n","affected":[{"package":{"ecosystem":"npm","name":"ranux-dev"},"versions":["5.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"7efe69b0f79537140a0b1fea3ab61c5bec3940ccb859c7046249094b99159bb2","tlsh":"8ef0c011cc60886315cc69d49c9901076bb0481b0e04fc2c33de661cabdd0ef31b976c"},{"path":"config.js","sha256":"8e192a5371b686e15d2c8415b0efa866201221e31e962ce849876a38178a377e","tlsh":"7db2a6867bc13c52254747f73717f6e8e52a2c8576c8188ef200b85cf9d9a21ebad271"}],"package_integrity":[{"filename":"ranux-dev-5.0.0.tgz","hashes":{"sha1":"241bc1c44f85153d0154fa00b2f895981db2cf51","sha512_sri":"sha512-Y8MDIFEHu3NAknpzCEm+q5VULcDA/lcmyAOYmUA8Cf6e1ptMi/gw1jpH5GXrCq0TrjXKaooBNhcJ3goYdfUjLQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ranux-dev/v/5.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018371","import_time":"2026-08-19T05:13:49.801244443Z","modified_time":"2026-08-19T04:59:57Z","sha256":"4dde928a7de2064f13b18847a56607605bd33f1331a57bb0be0ccf585fa5d86f","source":"amazon-inspector","versions":["5.0.0"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0