MAL-2026-14387Malicious code in @opap/player-kyc-widget (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
3.999.999 | archived | — | — | VIP 下载 |
| Ecosystem | Package | Version |
|---|---|---|
| npm | @opap/player-kyc-widget | 3.999.999 |
{"schema_version":"1.7.4","id":"MAL-2026-14387","published":"2026-08-23T20:00:33Z","modified":"2026-08-24T05:22:15.591485211Z","summary":"Malicious code in @opap/player-kyc-widget (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (abfe2a5c5b34e28b415fb39f20acea1ec320ef85aeb9577c9a52153630f964fc)\nThe package's postinstall script runs automatically on `npm install` and collects host identifiers (hostname, username, cwd, platform, arch) from the installer, then transmits them off-host through two channels to a hardcoded Burp Collaborator subdomain `k5qrs9i96xtw61nb3bbwwualqcw3kt8i.oastify.com`: (1) an HTTPS GET carrying a base64-encoded payload in the query string, and (2) a DNS lookup where the fingerprint is hex-encoded and split into <=60-char labels prepended to the callback host, providing a covert channel that works even when outbound HTTP egress is blocked. The version number 3.999.999 published to the public `@opap` scope is the canonical shape of a dependency-confusion attack targeting a private internal scope of the same name.\n\n## Source: ossf-package-analysis (98e627cea85331a67652aa65927058579efe7046253a9ef22cb70b1d73916885)\nThe OpenSSF Package Analysis project identified '@opap/player-kyc-widget' @ 3.999.999 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","affected":[{"package":{"name":"@opap/player-kyc-widget","ecosystem":"npm"},"versions":["3.999.999"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"dda4845548db484e4c259831fa9d6f90f4d0d03dd19fb4f50c294428fd81c237","tlsh":"d731576611f0223015ea34d0434b1199576be25b5b65f9d4f54e03085f8aab487725fa"}],"package_integrity":[{"filename":"player-kyc-widget-3.999.999.tgz","hashes":{"sha1":"f8bc01f36e529b94d91009b1339a6fb311159b50","sha512_sri":"sha512-CiEVyweEy7rqSL3Q7EuedoYv8Ltao+IViHjp3/e4U7AU8gRf9DD2TFf0cw9EXsylaTlZoMUvSnFVCIwM25icSA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@opap/player-kyc-widget/v/3.999.999"}],"database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-23T20:07:45.140609589Z","modified_time":"2026-08-23T20:00:33Z","sha256":"98e627cea85331a67652aa65927058579efe7046253a9ef22cb70b1d73916885","source":"ossf-package-analysis","versions":["3.999.999"]},{"id":"IN-MAL-2026-018590","import_time":"2026-08-24T05:20:12.557261485Z","modified_time":"2026-08-24T05:04:38Z","sha256":"abfe2a5c5b34e28b415fb39f20acea1ec320ef85aeb9577c9a52153630f964fc","source":"amazon-inspector","versions":["3.999.999"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0