MAL-2026-4595

    Dashboard / Malicious Package / MAL-2026-4595

    MAL-2026-4595

    Published: 25 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in koishi-plugin-fusheng-count (npm)

    Details: Source: amazon-inspector (060196a35f8eb94f7e91f892daf62aee8e293d16130565dfbc837877df264db5) lib/index.js contains a base64-obfuscated hardcoded user ID (`Buffer.from("Mjc1OTcyMDE2MQ==", "base64").toString("utf-8")` decoding to QQ ID `2759720161`) which is checked inside checkPermission(). When session.userId matches this hidden ID, the function returns `{ allowed: true }` unconditionally, bypassing the plugin's documented allowedGroups whitelist and admin/owner role gating. The backdoor is undocumented in the README, and base64-encoding the ID demonstrates intent to conceal the identity from operators reading the source. Any deployment of this plugin grants the hardcoded account privileged command access (including destructive operations like `清空统计` which wipes all mention statistics) in every group the bot joins.

    Affected packages

    Package

    Name: koishi-plugin-fusheng-count

    Purl: pkg:npm/koishi-plugin-fusheng-count

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.9
    MAL-2026-4595 | CVE-DB