{"id":"MAL-2025-6214","summary":"Malicious code in ecinc-cloud-moaxmpp (npm)","details":"Package exhibits multiple malicious behaviors: Office doc access/encryption, DB interaction, local storage clearing, arbitrary code execution, /dev/shm ref. The code includes a native bridge that allows it to execute arbitrary SQL queries on a mobile device’s database when used within a specific mobile application context. The `ecmoaxmpp.umd.js` file revealed a highly suspicious pattern. The code includes a function that checks if `window.mappType` is not equal to `'web'`. When this condition is met, it proceeds to call `window.$wv.databaseHandle`, a function that acts as a bridge to a native mobile application. The methods invoked through this bridge include 'execute', 'rawQuery', 'rawInsert', 'rawUpdate', and 'rawDelete', all of which indicate direct, raw access to a mobile device’s database.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (278b09ddb42295dff2bd8c843131f7f3c9d4d793bb42dd797adbc9c6c825a656)\nThe package was found to contain malicious code or consuming dependency that contains malicious code\n","modified":"2026-07-08T23:01:49.042384432Z","published":"2025-07-15T09:15:00Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-008488","modified_time":"2026-07-08T20:18:11Z","versions":["9.7.1"],"source":"amazon-inspector","sha256":"278b09ddb42295dff2bd8c843131f7f3c9d4d793bb42dd797adbc9c6c825a656","import_time":"2026-07-08T20:32:35.213396864Z"},{"sha256":"dce264b001af9019523477894adeb53df87d97c9235ecee1c58d7defd411ce42","import_time":"2026-07-08T22:51:26.196843688Z","id":"IN-MAL-2026-008837","modified_time":"2026-07-08T22:40:22Z","versions":["9.7.2"],"source":"amazon-inspector"}]},"references":[{"type":"REPORT","url":"https://platform.safedep.io/community/malysis/01K01T6C4JN4Q19HD1PAB151RZ"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ecinc-cloud-moaxmpp/v/9.7.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ecinc-cloud-moaxmpp/v/9.7.2"}],"affected":[{"package":{"name":"ecinc-cloud-moaxmpp","ecosystem":"npm","purl":"pkg:npm/ecinc-cloud-moaxmpp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["9.7.1","9.7.2"],"database_specific":{"indicators":{"package_integrity":[{"filename":"ecinc-cloud-moaxmpp-9.7.1.tgz","hashes":{"sha512_sri":"sha512-rE4XCyLPGHgVhMoTsgr7al/LUr+nsAcImUJe+EwxZS1aUlXyRmdgJhGacWAsfKNtgb5KQne79ARomJpOWJMx8w==","sha1":"ca7372705eb2a461b90262364397f7226a439dc7"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ecinc-cloud-moaxmpp/MAL-2025-6214.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}