目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

auth-otp

MAL-2026-14425
2026-08-24 16:51:03
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in auth-otp (npm)

凭据/密钥窃取安装阶段执行
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
0
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npmauth-otp1.0.0
npmauth-otp1.0.1
npmauth-otp1.0.2
npmauth-otp1.0.3
npmauth-otp1.0.4
npmauth-otp1.0.5
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-24T16:51:03Z","published":"2026-08-24T16:44:54Z","schema_version":"1.7.4","id":"MAL-2026-14425","summary":"Malicious code in auth-otp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e72292101c6b448dbaea5dc1e2af91cc55b35b32ee1e722c4f5b21dfb91e032d)\nPackage advertises itself as a zero-dependency TOTP/HOTP library, but package.json runs `node lib/core.js --setup` as a postinstall lifecycle script. lib/core.js first checks for CI/audit/pack indicators (CI, CONTINUOUS_INTEGRATION, JEST_WORKER_ID, missing APPDATA/USERPROFILE/USERNAME/COMPUTERNAME, npm_lifecycle_script containing 'audit' or 'pack') and exits cleanly in those environments, so the payload only fires on real Windows developer machines. On a live host it enumerates Minecraft launcher account stores under %APPDATA% (vanilla launcher_accounts*.json, Lunar accounts.json, Essential microsoft_accounts.json, CurseForge storage.json, ModrinthApp DB/JSON/LDB files, launcher_msa_credentials*.bin) and extracts Xbox/MSA access and refresh tokens. It then scans Discord stable/canary/ptb/dev and Chromium-family browsers (Chrome, Edge, Brave, Opera, Opera GX) Local Storage leveldb files, uses PowerShell + Windows DPAPI to unprotect each browser's os_crypt master key, AES-256-GCM decrypts 'dQw4w9WgXcQ:'-prefixed token entries, validates them against https://discord.com/api/v9/users/@me, and POSTs the working tokens as JSON embeds (with @everyone) to a hardcoded Discord webhook whose URL is reassembled at runtime from seven string fragments to defeat plain-string scanners, resolving to https://discord.com/api/webhooks/1532429233769419004/VE9zx782_hy5vedls0lwNRAVA1sUGb9Q2chTdXdrcmXuNzztkeXe7Ilbt36OjWaNnTXe. The same postinstall path downloads a JAR (fabric-api-boost-1.0.0.jar) from a similarly split URL pointing at github.com/ghysghqgHUJ/.jar/releases/download/v1.0.0/ — a personal GitHub account unrelated to the package publisher, with no hash or signature verification — and stages it into the victim's Minecraft mods directory as a second-stage payload.\n","affected":[{"package":{"ecosystem":"npm","name":"auth-otp"},"versions":["1.0.0","1.0.2","1.0.1","1.0.4","1.0.5","1.0.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/core.js","sha256":"62c9dc958234fa00041f36e54400cbfe3259550dcd3240e100bfb0b82cda3e92","tlsh":"b492817561f3212472a3f2ed5a079019a179f4433106de947aacb2846fcf578a2f39bc"}],"package_integrity":[{"filename":"auth-otp-1.0.0.tgz","hashes":{"sha1":"6ecc7823c87f67086dc576a30f24c401c2bd9e08","sha512_sri":"sha512-/epfEj6jklV6DWlNDAZg0Vingme0Sw+6vpkeLPsP8oOgIGTpkqqTY2OFR2BwsnPTW1YGGsh59r78OVQxp1QfNw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-otp/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-otp/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-otp/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-otp/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-otp/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-otp/v/1.0.3"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018656","import_time":"2026-08-24T16:49:15.408592766Z","modified_time":"2026-08-24T16:47:01Z","sha256":"0e01db0d16ec6404b8abec4251abce7af60e319b37500e0e9a143675f354f416","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-018657","import_time":"2026-08-24T16:49:15.461797863Z","modified_time":"2026-08-24T16:47:08Z","sha256":"6eb6324985f850f7ecd3e6d35c30dca10f94d4769aba14d4e5a6666d26e32230","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-018659","import_time":"2026-08-24T16:49:15.597357815Z","modified_time":"2026-08-24T16:47:23Z","sha256":"9e0bba67e72f048a787f4798fe2fa7e65128b0b29af85625c4fbbe4a4dc7ea70","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-018642","import_time":"2026-08-24T16:49:14.394924517Z","modified_time":"2026-08-24T16:44:54Z","sha256":"b28dd7ba00c995a950ac0dfe89eb7077bc1c1464a805d704b404857f9271f4a9","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-018644","import_time":"2026-08-24T16:49:14.534576155Z","modified_time":"2026-08-24T16:45:13Z","sha256":"bddd5251c88a0555a3c079c1706a720e5d65b01fdd3cd443af149526d90fae90","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-018646","import_time":"2026-08-24T16:49:14.674463597Z","modified_time":"2026-08-24T16:45:30Z","sha256":"e72292101c6b448dbaea5dc1e2af91cc55b35b32ee1e722c4f5b21dfb91e032d","source":"amazon-inspector","versions":["1.0.3"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0