{"id":"MAL-2026-10465","summary":"Malicious code in node-sysmon-native (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (612887c8528ff96b3bc3a61d678b6376099480c080d2d8a0960fe7798ac25f33)\nOn module load, index.js reconstructs a hex-encoded URL (Buffer.from('687474703a2f2f3135322e35332e3132302e39302f636d64','hex')) that decodes to http://152.53.120.90/cmd and enters an asynchronous polling loop that GETs /commands from that host, executes each returned command via spawnSync('bash', ['-c', cmd]) with a 55-second timeout and 5MB output buffer, and POSTs the stdout, stderr, and exit code back to /results. Any consumer that require()s this package grants the operator of 152.53.120.90 arbitrary shell execution on the host, with output exfiltration. The destination is a bare IP address reconstructed at runtime from a hex string to hide it from static scanners, and the package's declared 'sysmon-native' purpose provides no legitimate reason for polling a hardcoded remote host for shell commands.\n","modified":"2026-07-13T18:16:55.603905696Z","published":"2026-07-13T17:36:43Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-010266","import_time":"2026-07-13T18:10:12.099777135Z","modified_time":"2026-07-13T17:36:51Z","sha256":"3f8a6c11a70645f277c02b86ac449237316b52e4e37b685526a0e2acccbaa305"},{"versions":["1.0.1"],"id":"IN-MAL-2026-010265","import_time":"2026-07-13T18:10:11.988402598Z","modified_time":"2026-07-13T17:36:43Z","sha256":"612887c8528ff96b3bc3a61d678b6376099480c080d2d8a0960fe7798ac25f33","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-010268","import_time":"2026-07-13T18:10:12.234112449Z","modified_time":"2026-07-13T17:37:10Z","sha256":"e1356ef95d176b270c43ef0f201811f2a3a958e537461de66496929e31369723"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/node-sysmon-native/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/node-sysmon-native/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/node-sysmon-native/v/1.0.2"}],"affected":[{"package":{"name":"node-sysmon-native","ecosystem":"npm","purl":"pkg:npm/node-sysmon-native"},"versions":["1.0.0","1.0.1","1.0.2"],"database_specific":{"indicators":{"evidence_files":[{"path":"sysmon.cc","sha256":"afdc004c06a7a42f5763d83766e107cd24bc139c12cd714cec167ed0a5e19610","tlsh":"404160e5e5aea8d5d2ef0b687343c5a0a15f610b12d6cd10fd8ea0981f4845492f3b6b"}],"package_integrity":[{"hashes":{"sha1":"b13f0038b65cca5b9bde920c88eb757f1ea0e1bf","sha512_sri":"sha512-ll8+3SN4AupUubGSwGjMc4dOEovY69Q4txfxWOlLl0ahrTbm0SAzRCjCDYQNfHG3AN+rnDxyzlLQFMmvFsP9MA=="},"filename":"node-sysmon-native-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/node-sysmon-native/MAL-2026-10465.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}