{"id":"MAL-2026-10473","summary":"Malicious code in claude-team-tracker (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a7e9f6179a67a2904c37bd9cff22174a8c57755972fc878047993c35c03f5544)\nOn install, postinstall.js opens /dev/tty directly to bypass npm's stdio piping and force-spawns a 'setup' subcommand with the real terminal attached. The setup flow installs aggressive persistence (cron + systemd --user with `loginctl enable-linger` on Linux; LaunchAgent with KeepAlive on macOS) for a long-polling daemon. The daemon polls tracker.clawodoo.com/api/commands and, upon receiving an `update_client` command, executes `npm install -g \u003cserver-supplied package@version\u003e` via execSync and then re-execs itself (spawn detached on process.argv) — giving the operator of tracker.clawodoo.com a stable remote-code-push channel that runs any package/version system-wide on every installed host. Separately, lib/rate-limits.js reads the user's Anthropic OAuth access token from ~/.claude/.credentials.json, calls api.anthropic.com/api/oauth/profile to retrieve the account's email, full name, account UUID, organization UUID, organization name, and subscription tier, and reporter.js POSTs that identity profile plus machine_id and hostname to tracker.clawodoo.com/api/report. The combination — persistent server-controlled remote update channel plus exfiltration of Anthropic account identity and org membership to a hardcoded author endpoint — is an installer-side backdoor with credential-adjacent identity disclosure regardless of the package's 'team usage tracker' framing.\n","modified":"2026-07-13T19:46:54.409512641Z","published":"2026-07-13T19:05:05Z","database_specific":{"malicious-packages-origins":[{"sha256":"a7e9f6179a67a2904c37bd9cff22174a8c57755972fc878047993c35c03f5544","source":"amazon-inspector","versions":["1.2.1"],"id":"IN-MAL-2026-010291","import_time":"2026-07-13T19:37:58.303489535Z","modified_time":"2026-07-13T19:05:05Z"},{"id":"IN-MAL-2026-010292","import_time":"2026-07-13T19:37:58.357868389Z","modified_time":"2026-07-13T19:05:13Z","sha256":"fece5b3056601b0c9ff7a584f268d1c3807d1fbd838f0a428282534f50ebd38b","source":"amazon-inspector","versions":["1.2.0"]},{"id":"IN-MAL-2026-010293","import_time":"2026-07-13T19:37:58.411620473Z","modified_time":"2026-07-13T19:05:21Z","sha256":"f7c2919961771195b62d25929e5c43b28c088cb65a1c9904aa1e59616243f598","source":"amazon-inspector","versions":["1.2.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claude-team-tracker/v/1.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/claude-team-tracker/v/1.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/claude-team-tracker/v/1.2.2"}],"affected":[{"package":{"name":"claude-team-tracker","ecosystem":"npm","purl":"pkg:npm/claude-team-tracker"},"versions":["1.2.1","1.2.0","1.2.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"claude-team-tracker-1.2.1.tgz","hashes":{"sha1":"7b52223104e3872d0a11830a8119564fc81ce1fe","sha512_sri":"sha512-5hOWoyrO+S6jGJGg0/PkBWTm3kxy3Q+JLStWL/D8KqXHa6wm51TVyOLKGm606n0ZTCG+/J3XZxQ5K+gGD0rgTQ=="}}],"evidence_files":[{"tlsh":"40514eaf06ff6a3501b265c8e3334032293be2033105e8e4b75d92152f0e55899b2ded","path":"lib/poller.js","sha256":"5a9a32850eaea296a2a17da850bd8834a865aac786aca64a6a25217f22e77a61"},{"path":"lib/rate-limits.js","sha256":"87785baf145803d419b332af06beb84357fb38716500af4c9538f685ab141d0d","tlsh":"af71219781fa30198a91bd9ae74781213136d41336c2edd473bca5812f1bb9492b3fe5"},{"tlsh":"66f193a087f6a1391cf216963b5b003b2a0be1572916e8e873dd43454fcec14a1b36fe","path":"lib/setup.js","sha256":"ab74c48d834ee541f95a16e289c36dea493202af90f0e9a2163e362a808156d1"},{"tlsh":"e131000a09ff2b2536f118d9eb878032ac16d013220ca7f8b5dfc3547f4a1649a925fb","path":"bin/postinstall.js","sha256":"ba2efd92bc3748a09b99d82f7a58754584b507caf4cebc8f131269d15b5d176c"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claude-team-tracker/MAL-2026-10473.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}