目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%
← 返回恶意软件包
npm active

@epic-common/observability-node

MAL-2026-6562
2026-08-14 15:40:14
OpenSSF Malicious Packages
该软件包被识别为恶意包。建议隔离受影响环境,并排查凭据泄露和异常网络连接。

Summary

Malicious code in @epic-common/observability-node (npm)

凭据/密钥窃取文件/数据外传
AI 分析整理qwen3.6
基于上游报告生成,请以下方原始证据为准。
公开使用量数据
统计周期
last-week
下载量
9
数据源
npmjs.org
下载量只代表仓库活动度,不等于已被入侵的安装数量。
受影响版本
EcosystemPackageVersion
npm@epic-common/observability-node0.0.1
npm@epic-common/observability-node0.0.1-security
npm@epic-common/observability-node10.10.1
npm@epic-common/observability-node10.10.2
恶意行为说明OpenSSF OSV
上游来源证据
展开原始 OSV JSON
{"modified":"2026-08-14T15:40:14Z","published":"2026-06-29T04:21:26Z","schema_version":"1.7.4","id":"MAL-2026-6562","summary":"Malicious code in @epic-common/observability-node (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (73d7457ccefffe2de1f0464f21ac2eadfb981be593d2b34ceb0d5cde1174da0b)\nPackage targets the private @epic-common scope (Epic Games) and is published to the public npm registry as a dependency-confusion vehicle. On import of the./api subpath, top-level code enumerates all process.env keys and POSTs the full key list, hostname, cwd, platform, and arch to https://otel-collector.ramanmgg1.workers.dev/da32b89f213c91a0. For every env var whose name matches a credential-shaped pattern (TOKEN|SECRET|KEY|PASSWORD|AUTH|AWS|GCP|AZURE|DATABASE|REDIS|MONGO|STRIPE|JWT|SESSION|COOKIE|WEBHOOK|...), it additionally transmits the variable name, value length, first 2 characters, and SHA-256 of the value. The name+length+prefix+hash tuple enables offline brute-force/dictionary recovery of low-entropy or fixed-format secrets (e.g., AWS access keys). The package re-exports the real OpenTelemetry API so dependent builds appear functional, masking the exfiltration. Any installer or build pipeline whose resolver pulls @epic-common/observability-node from the public registry instead of an internal one will execute this beacon on import. Self-described as a security-research PoC, but the README/intent self-label does not change the installer-side harm: env-var inventory, host identifiers, and credential fingerprints leave the installer's machine to a non-first-party endpoint without consent.\n","affected":[{"package":{"ecosystem":"npm","name":"@epic-common/observability-node"},"versions":["0.0.1","10.10.1","10.10.2","0.0.1-security"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"e9173a7d3f71bd90464bde21130a4dc0cb8d226c7185446c552220213efc3e45","tlsh":"1a017608c2148c1309ea56e12a399933a6624c5b8c597e0833ea03ad8b4d77b21fe15e"},{"path":"dist/api/index.mjs","sha256":"9e8757ab3929744c14cee6526b4e050944329b3faa027d3b3dcf60f389248f7f","tlsh":"7da1b7466cf5127106d3d0e97a5e6142f17f84531654a0b8790da70c2fdd6ac83fe2c7"}],"package_integrity":[{"filename":"observability-node-10.10.2.tgz","hashes":{"sha1":"34908dfdfd1bd6940c82377f48d457d074a821cc","sha512_sri":"sha512-RhrakWpWSOP7ZdVeyv7kZ1bO4pdI0Gq1tfrVHHiWfgQR48rUwUBHaFxqlQhxiEEXnow2NnH3bHA1gHj5fQeJvw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@epic-common/observability-node/v/10.10.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@epic-common/observability-node/v/10.10.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@epic-common/observability-node/v/0.0.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","sha256":"73d7457ccefffe2de1f0464f21ac2eadfb981be593d2b34ceb0d5cde1174da0b","import_time":"2026-06-29T05:07:07.00655198Z","id":"IN-MAL-2026-007721","modified_time":"2026-06-29T04:21:26Z","ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["10.10.2"]},{"source":"amazon-inspector","sha256":"dec788bdcb2fa3098e1493c67e5b6e8a83f5495046e6cd3cf90fc654437fe221","import_time":"2026-06-29T05:07:07.124804403Z","id":"IN-MAL-2026-007722","modified_time":"2026-06-29T04:21:35Z","ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["10.10.1"]},{"source":"amazon-inspector","sha256":"0f4a1e914881fb1693afbb25516bd91b8b76e78694c5595e44baaa4229c7b507","import_time":"2026-07-08T17:01:34.180851974Z","id":"IN-MAL-2026-008145","modified_time":"2026-07-08T16:33:35Z","versions":["0.0.1"]}]}}

数据来源:OpenSSF Malicious Packages · Apache-2.0