{"id":"MAL-2026-10549","summary":"Malicious code in abi-encode (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (afc61427f74a028242a032b9436c09c43b1df60fef5688aa5389ef107e899259)\nThe package advertises ABI encoding but on require() schedules a 37-second timer that decodes test/fixtures/keypairs.dat (base64-encoded stealer, staged to look like cryptographic test data) into ~/.cache-db/.node-sync/syncd.js with mode 0700 and spawns it detached under node. Persistence is installed by appending a crontab entry (Linux) that re-runs the dropped script every 12 hours, or by registering a scheduled task named WinNodeSync (Windows). The decoded payload walks the installer's home directory for files matching wallet/seed/credential extensions and keywords (.env,.key,.keystore,.pem, seed, mnemonic, wallet, private, metamask, phantom, ledger, trezor, PRIVATE_KEY, MNEMONIC, SECRET, TOKEN), RSA-encrypts matches, and uploads them to attacker-controlled IPFS via api.pinata.cloud using an embedded Pinata API key/secret, with three hardcoded IPFS CID dead drops as fetch fallbacks. The 37-second delay, fake-fixture staging, hidden home-directory drop path, and cross-platform persistence together confirm evasive malicious intent unrelated to ABI encoding.\n","modified":"2026-07-14T18:49:32.356352290Z","published":"2026-07-14T05:21:03Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","sha256":"9f6a627f36e6f2a50a631e6e3acd882dd77a6ab722a83f156dba8d2f3af9cc81","import_time":"2026-07-14T05:49:19.756277329Z","id":"IN-MAL-2026-010398","modified_time":"2026-07-14T05:21:12Z","versions":["1.0.2"]},{"id":"IN-MAL-2026-010397","modified_time":"2026-07-14T05:21:03Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"afc61427f74a028242a032b9436c09c43b1df60fef5688aa5389ef107e899259","import_time":"2026-07-14T05:49:19.631598116Z"},{"versions":["1.0.1"],"source":"amazon-inspector","sha256":"cb701af1570caa4be98dc0c57d547ce9d04f3ce12cfe126d7ecd7d80b5a5f621","import_time":"2026-07-14T05:49:19.843555873Z","id":"IN-MAL-2026-010399","modified_time":"2026-07-14T05:21:21Z"},{"sha256":"2942c9be2d842ce31808ede5c18a0a3a225ea1b9e6df5b760f72475c9e9dc9fb","import_time":"2026-07-14T18:28:27.264860776Z","id":"IN-MAL-2026-010537","modified_time":"2026-07-14T17:54:54Z","versions":["1.0.3"],"source":"amazon-inspector"},{"import_time":"2026-07-14T18:28:27.520707037Z","id":"IN-MAL-2026-010539","modified_time":"2026-07-14T17:55:12Z","versions":["1.0.4"],"source":"amazon-inspector","sha256":"33251c3218d3117a4da78d8c7f8065173a9f5971402c560e89f16c081082e9d7"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/abi-encode/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/abi-encode/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/abi-encode/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/abi-encode/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/abi-encode/v/1.0.4"}],"affected":[{"package":{"name":"abi-encode","ecosystem":"npm","purl":"pkg:npm/abi-encode"},"versions":["1.0.2","1.0.0","1.0.1","1.0.3","1.0.4"],"database_specific":{"indicators":{"package_integrity":[{"filename":"abi-encode-1.0.2.tgz","hashes":{"sha1":"e6d6042c30c5ba0b84cf58d9115ba770c2faf8ff","sha512_sri":"sha512-LKdvmCZCxI8BSQwED/0YYAqwjx6KZNtFzKxhkDW0nmmdP+2uoWJWhMq5nNKE7vGIqfdnButKfW/71InYOFtI6w=="}}],"evidence_files":[{"path":"index.js","sha256":"464fe455f640ff325eb2f924512ee5d921948e3fe54687ebcce8f38af697f799","tlsh":"ba61675a39e323624b66b0f9856b5818a5fbb0031344ca5d764c81d51f4483c4ffbfb4"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abi-encode/MAL-2026-10549.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}