{"id":"MAL-2026-10713","summary":"Malicious code in @hibachi-xyz/config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2012c3b3a43f28209edf1c4b6fdbb0477c7c31f7574e37293cf7dd324f7f1e2f)\nOn require of the package's main entry, top-level code enumerates process.env and collects values whose keys match a credential-shaped regex (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, CIRCLE, GITHUB, DB, RDS, SENTRY, PYPI, NPM, DOCKER, KUBE, TUNNEL, CF_). It also invokes child_process.execSync to run `whoami && id && cat /proc/1/cgroup` and collects hostname and username. The combined JSON payload is POSTed to https://jorijo.xyz:8443/t with TLS certificate verification disabled (rejectUnauthorized:false). The 99.0.0 version number under the @hibachi-xyz scope is consistent with a version-inflation typosquat or scope hijack of legitimate hibachi packages.\n\n## Source: ossf-package-analysis (4b4af2f9414079b2062bec53821ecf7f67924011261a4f0430450b8415e9b07e)\nThe OpenSSF Package Analysis project identified '@hibachi-xyz/config' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-07-17T03:19:28.147564954Z","published":"2026-07-16T11:16:53Z","database_specific":{"malicious-packages-origins":[{"versions":["99.0.0"],"source":"amazon-inspector","sha256":"2012c3b3a43f28209edf1c4b6fdbb0477c7c31f7574e37293cf7dd324f7f1e2f","import_time":"2026-07-16T18:54:00.021233711Z","id":"IN-MAL-2026-010703","modified_time":"2026-07-16T18:34:43Z"},{"versions":["99.0.0"],"source":"ossf-package-analysis","sha256":"4b4af2f9414079b2062bec53821ecf7f67924011261a4f0430450b8415e9b07e","import_time":"2026-07-17T03:07:34.252770881Z","modified_time":"2026-07-16T11:16:53Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@hibachi-xyz/config/v/99.0.0"}],"affected":[{"package":{"name":"@hibachi-xyz/config","ecosystem":"npm","purl":"pkg:npm/%40hibachi-xyz/config"},"versions":["99.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha1":"5269e19f1c7d9a0955f6c7afe7ae2e6f814b6ea9","sha512_sri":"sha512-gKJzxLzllZrxlbH27fLw9iJIqTVgBVJYyj+9WvZJsT2O8HulRLkAlHeHIj0ZJ7oPy6+hhr6i17pVmWM/Rm0URQ=="},"filename":"config-99.0.0.tgz"}],"evidence_files":[{"sha256":"0d800f2db51cc9935282ab475e18151d9f169c6b40d5af666b6f405ab9b1fa5e","tlsh":"2111e3e0c7e591b452b2a2e494efc017b2e3cc207156ede0368d5ba23e92d9404771f3","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hibachi-xyz/config/MAL-2026-10713.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}