{"id":"MAL-2026-10714","summary":"Malicious code in @hibachi-xyz/sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (54956c91d0cedbe9097a2a8f7fa864382bd3b5a91ba7ccbe4a0219081be711f9)\nindex.js (the package main) executes at require-time and performs credential and host exfiltration. It iterates process.env and filters keys matching a broad credential regex (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, CIRCLE, GITHUB, DB, RDS, SENTRY, PYPI, NPM, DOCKER, KUBE, TUNNEL, CF_, etc.), collects hostname and username, and runs `whoami && id && cat /proc/1/cgroup` via child_process.execSync to fingerprint the user/container/CI runner. The collected data is POSTed to https://jorijo.xyz:8443/t with TLS certificate verification disabled (rejectUnauthorized:false). The version number (99.0.0) and scoped name are consistent with a typosquat/impersonation of an @hibachi-xyz SDK.\n\n## Source: ossf-package-analysis (c11bfc518d9b46d575a8f0354528c134382b02809f4958c0029a128d7177d79d)\nThe OpenSSF Package Analysis project identified '@hibachi-xyz/sdk' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-07-17T03:19:25.979414111Z","published":"2026-07-16T11:10:58Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-16T18:34:17Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"54956c91d0cedbe9097a2a8f7fa864382bd3b5a91ba7ccbe4a0219081be711f9","import_time":"2026-07-16T18:53:59.902630003Z","id":"IN-MAL-2026-010700"},{"modified_time":"2026-07-16T11:10:58Z","versions":["99.0.0"],"source":"ossf-package-analysis","sha256":"c11bfc518d9b46d575a8f0354528c134382b02809f4958c0029a128d7177d79d","import_time":"2026-07-17T03:07:33.998474067Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@hibachi-xyz/sdk/v/99.0.0"}],"affected":[{"package":{"name":"@hibachi-xyz/sdk","ecosystem":"npm","purl":"pkg:npm/%40hibachi-xyz/sdk"},"versions":["99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hibachi-xyz/sdk/MAL-2026-10714.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"0d800f2db51cc9935282ab475e18151d9f169c6b40d5af666b6f405ab9b1fa5e","tlsh":"2111e3e0c7e591b452b2a2e494efc017b2e3cc207156ede0368d5ba23e92d9404771f3","path":"index.js"}],"package_integrity":[{"hashes":{"sha1":"aa6f289844ac0efd8e7f2ea9fcdf8e283e909ae4","sha512_sri":"sha512-WoS8A8ftezc1gWcogP5cmPZy0iLVanM1AXRJ/ihTYZqPV/oztaCgqRNgRBH+G0pL6PSj4Xu4u6SjGh7PhyZpcw=="},"filename":"sdk-99.0.0.tgz"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}