{"id":"MAL-2026-10425","summary":"Malicious code in trinity-scheme (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5d576c0487668f599137a479e17ddc1335935fdec631f7d5adfa9e73049d7652)\nOn npm install, the package's preinstall lifecycle reads a hex-encoded `command` string from preinstall.json, decodes it via Buffer.from(..., 'hex'), and passes the decoded shell command to child_process.exec. The decoded payload collects the installer's `whoami`, `pwd`, and `hostname` output and POSTs the values to the hardcoded endpoint https://eo7o7j442dx6yl6.m.pipedream.net/. The command is stored in hex form to evade plain-text scanning; the package otherwise provides no functionality consistent with its declared name.\n","modified":"2026-07-13T07:47:04.838603177Z","published":"2026-07-13T06:55:05Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-13T07:40:12.534272296Z","modified_time":"2026-07-13T06:55:05Z","sha256":"5d576c0487668f599137a479e17ddc1335935fdec631f7d5adfa9e73049d7652","source":"amazon-inspector","versions":["20.0.0"],"id":"IN-MAL-2026-009842"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/trinity-scheme/v/20.0.0"}],"affected":[{"package":{"name":"trinity-scheme","ecosystem":"npm","purl":"pkg:npm/trinity-scheme"},"versions":["20.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"34a1435202961e9d224c404e2ff51ffb94525b25","sha512_sri":"sha512-Rlyc4BZYt/obEHvepwcIrWcbKmor8i8iM4kA1DYmC9cRWGiZhomd9XutZ8IfXRejtBuEp3BQIxfkFPHrt2/xew=="},"filename":"trinity-scheme-20.0.0.tgz"}],"evidence_files":[{"sha256":"913112caf871d2cd2a23e6becb67ec28401cc294e424d6bf22985c4e1f404bc2","tlsh":"edf07d052dfa1237403b20a54a47580b318ad901313edda2bbee5b516fc5c64cca36c9","path":"preinstall.js"},{"path":"preinstall.json","sha256":"1eb5ca179df8182f96faa1d513b2030b45148e9f7a0f8e399f530e49ac13efd5","tlsh":"d8d022fc91c0ca87a138008d0be97e092e425ba28cb10e72d02cad28ac08e003bbc02c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/trinity-scheme/MAL-2026-10425.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}