目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

create-coin

MAL-2026-14372
2026-08-23 03:15:07
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in create-coin (npm)

凭据/密钥窃取安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
138
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmcreate-coin20.1.1
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-23T03:15:07Z","published":"2026-08-23T03:15:07Z","schema_version":"1.7.4","id":"MAL-2026-14372","summary":"Malicious code in create-coin (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d92da1d80f455caae769107e4b3ff99c003a296f1238728cfc5521d5be06c380)\nPackage create-coin@20.1.1 registers a postinstall hook that runs build/payload.node.js during npm install. The script performs anti-analysis guards (bails out on CI/GitHub Actions env vars, /.dockerenv, container cgroups, or fewer than four environment variables), sleeps a randomized 10-30 seconds, then reads the installer's ~/.npmrc (or %USERPROFILE%\\.npmrc), enumerates every process.env entry, and reads project files including package.json, package-lock.json,.env, and src/config.*. It also collects host reconnaissance via os.hostname(), os.userInfo(), and child_process output of uname/id, plus open localhost port probes. All collected data is POSTed over HTTPS to the hardcoded endpoint https://random-name.trycloudflare.com with rejectUnauthorized:false, and a.ran lock file is written for idempotency. Exceptions are swallowed and exit code is forced to 0 so npm install appears successful. The package.json description claims the package is a \"netbsd-x64 build for esbuild\" while the shipped code has no relationship to esbuild, indicating typosquat / platform-package impersonation of the esbuild family.\n","affected":[{"package":{"ecosystem":"npm","name":"create-coin"},"versions":["20.1.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"build/payload.node.js","sha256":"9653b29051064bf5d0adf870033b496b49406e14c58b07480a15ebc0c2ebe80b","tlsh":"bcb122da5aea21717a23b1b6466f10097177e2530286dad4bc9cd1419fb0b78236acfc"},{"path":"package.json","sha256":"5d0cb9cd0e95c389679840a799d1ff5b4dd7d83bd7b28d97efaf1f9e227688c5","tlsh":"2de0c2304a10592336c85a991c79864ae6728c3748817804279b115886ab2ba24bf66e"}],"package_integrity":[{"filename":"create-coin-20.1.1.tgz","hashes":{"sha1":"d288569563bd81f59ee9fce96a2857502e7735c1","sha512_sri":"sha512-XQ5fY7VVinbK6ghueipMvrTVqUaUoM2utCG+F9XeukZXJMNE/LbigHPnx7JlGJenvw3efJDxwRw0wVM+ziJqdA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/create-coin/v/20.1.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018572","import_time":"2026-08-23T03:25:56.486359813Z","modified_time":"2026-08-23T03:15:07Z","sha256":"d92da1d80f455caae769107e4b3ff99c003a296f1238728cfc5521d5be06c380","source":"amazon-inspector","versions":["20.1.1"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0