目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

o0o9

MAL-2026-14277
2026-08-19 07:50:57
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in o0o9 (npm)

AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
204
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmo0o91.8.0
npmo0o92.0.1
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-19T07:50:57Z","published":"2026-08-19T07:21:14Z","schema_version":"1.7.4","id":"MAL-2026-14277","summary":"Malicious code in o0o9 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118)\nThe package's main entry index.js imports child_process at the top of the file and invokes spawn(\"powershell\",...) as a top-level side effect (line 27). Loading the module via require/import causes an unprompted PowerShell process to launch on the installer's machine, which is a Windows-focused code execution vector wholly unrelated to any legitimate library function. This is the shape of an install/import-time execution payload rather than an API a caller must opt into.\n","affected":[{"package":{"ecosystem":"npm","name":"o0o9"},"versions":["1.8.0","2.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"3d021550c3cc60b53cc3ba05c56418eb3012fca19f2496a156c6730736a47a93","tlsh":"1e318736639b6d34a2314990a856642b689fc130736424d0d51c713bff1b83b42779dd"}],"package_integrity":[{"filename":"o0o9-2.0.1.tgz","hashes":{"sha1":"f184b39b51a2634201d269dd8dcdaa1657264b37","sha512_sri":"sha512-WL73hRdoiMONJnxdZnOQgCJgCjF8vKEL/qo3QYe1sNLmRPUes3VF4de7lYLQGCFQOtySVoWedabEsS8Atb8PgA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/o0o9/v/1.8.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/o0o9/v/2.0.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018390","import_time":"2026-08-19T07:48:47.011656424Z","modified_time":"2026-08-19T07:21:23Z","sha256":"a1d425848ef7172faf5f84ff9bd9017bf3ab1eb2343a5301ff0df1711d091118","source":"amazon-inspector","versions":["1.8.0"]},{"id":"IN-MAL-2026-018389","import_time":"2026-08-19T07:48:46.555687629Z","modified_time":"2026-08-19T07:21:14Z","sha256":"dc07d1bcb92034037f41bf30cf6bd67f5313276df6aeef3a805d4b52d757e22b","source":"amazon-inspector","versions":["2.0.1"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0