{"id":"MAL-2026-10449","summary":"Malicious code in auth-gen-next (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (49e38202e2579f6591dbc161817859bb99a212cbf6c1e5482b3271acf8fc4de0)\nThe package impersonates the pino logger (README assets, keywords, and internal filenames such as lib/proto.js, lib/multistream.js, lib/redaction.js, lib/transport.js, lib/writer.js are pino-branded) but its declared purpose is unrelated. On require, index.js loads lib/writer.js, which builds an object containing the full process.env, os.platform(), os.hostname(), os.userInfo().username, and non-internal MAC addresses, then unconditionally invokes context.data() from lib/content.js. That function issues an axios GET to https://pro-api.coinmarketcap.com/public-api/v1/ and eval()s a heavily obfuscated string (obfuscator.io-style string array with base64/XOR/RC4 decoders) that reconstructs a JSON-RPC eth_call transport, XOR-decodes the response, and spawns a child process using process.execPath to execute the retrieved payload. lib/writer.js additionally contains a hex-encoded fallback loader decoding to https://www.jsonkeeper.com/b/HY6M6. lib/content.js is heavily obfuscated (while(!![]), array-shift decoder) to hide the destinations and payload from review.\n","modified":"2026-07-13T15:49:13.577500773Z","published":"2026-07-13T14:20:42Z","database_specific":{"malicious-packages-origins":[{"versions":["1.7.13"],"id":"IN-MAL-2026-010258","import_time":"2026-07-13T15:30:30.888623176Z","modified_time":"2026-07-13T14:20:42Z","sha256":"49e38202e2579f6591dbc161817859bb99a212cbf6c1e5482b3271acf8fc4de0","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth-gen-next/v/1.7.13"}],"affected":[{"package":{"name":"auth-gen-next","ecosystem":"npm","purl":"pkg:npm/auth-gen-next"},"versions":["1.7.13"],"database_specific":{"indicators":{"package_integrity":[{"filename":"auth-gen-next-1.7.13.tgz","hashes":{"sha1":"38c22a054db80caf480a4328e9fd9cbd1be187f1","sha512_sri":"sha512-GY8Rjv+mBw5PUzYbUf5aNA85iEBIqZEsOSihM7rLfSPNW+SNm9QjwO978lwZ+y5Q8+g5Vt3aa+yliomFlsRH2A=="}}],"evidence_files":[{"tlsh":"38d2c8c93bd2f0a01222a0bb7d1b65a5e1359c89b3ccc088f7a6f458fd58758e179f54","path":"lib/content.js","sha256":"73ac5a03c700b28d5db8b03c3b4c8dc7377e1f468f4c983111666fcdfb90ba73"},{"sha256":"c8c0475aed9beb3f7d0a161ab916b85a56cc5bd0df05c7d7bf337e5f8729185d","tlsh":"942102b19792a41022301be248db4460bbd1f3553196405cb9fc86ca1bf3dd17155fb4","path":"lib/writer.js"},{"path":"package.json","sha256":"ffbdd61ea2a24056a212afd80208afce032cd0403a246f1218266e375102d76a","tlsh":"5d019c50cd25aea344c92593582a51876761cc5b5818fc2c33c7a36d0f5d57f15ff29c"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/auth-gen-next/MAL-2026-10449.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}