{"id":"MAL-2026-10718","summary":"Malicious code in @sciagent/cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (310123a94891174b8cfa55def38b6e916b89d43306a52793739f26289fe51e4d)\nscripts/postinstall.js fetches a ~10MB+ 'sciagent' executable over HTTPS from https://u250924-adc6-f977430f.westb.seetacloud.com:8443 (a rented seetacloud.com subdomain that does not match the package's declared publisher), writes it to ~/.sciagent/bin/sciagent, chmods it 0755, and the CLI shim subsequently spawns it. No hash, signature, or publisher check is performed on the fetched bytes; the URL is also overridable via a RELEASE_SERVER_URL environment variable. A fallback branch runs an unpinned `npm install -g @tencent-ai/codebuddy-code` at postinstall time and writes a wrapper that requires the resolved codebuddy-headless.js, so whatever version of that unrelated third-party package is current at install time is auto-installed globally and loaded by the sciagent CLI. Publisher metadata (gitee garva/research-agent, 'SciAgent Team') does not match either the seetacloud host or the poisondrinker/research-agent GitHub fallback referenced in the same script. Installing the package causes the installer's machine to execute opaque bytes retrieved from a non-publisher host at install time.\n","modified":"2026-07-16T19:19:58.148900214Z","published":"2026-07-16T18:42:59Z","database_specific":{"malicious-packages-origins":[{"sha256":"310123a94891174b8cfa55def38b6e916b89d43306a52793739f26289fe51e4d","source":"amazon-inspector","versions":["1.0.68"],"id":"IN-MAL-2026-010762","import_time":"2026-07-16T18:54:03.286279845Z","modified_time":"2026-07-16T18:43:39Z"},{"import_time":"2026-07-16T18:54:03.028064165Z","modified_time":"2026-07-16T18:42:59Z","sha256":"f293746cfa28ddea655cd5823c78429c8027bef305862c586699d48ffc74918c","source":"amazon-inspector","versions":["1.0.69"],"id":"IN-MAL-2026-010757"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@sciagent/cli/v/1.0.68"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@sciagent/cli/v/1.0.69"}],"affected":[{"package":{"name":"@sciagent/cli","ecosystem":"npm","purl":"pkg:npm/%40sciagent/cli"},"versions":["1.0.68","1.0.69"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-KaPhOgpBgjEVMIghjTQnTWwy4zFv3aWlYu7j3cL5MB7gecZHb6jddDYIIY4anfH5IYNHp9ASADEqYM1L2KosPQ==","sha1":"28a6084539ee4212708ca100c4c7cd1032032c93"},"filename":"cli-1.0.68.tgz"}],"evidence_files":[{"tlsh":"7bd2a98609fb21342b776a595b7b182631199403a30aed4cb98c47d52ff3a24cdd36ef","path":"scripts/postinstall.js","sha256":"bdeec73b0a8513cbb88aa58534d7cd243ab84f69ba1e816c3f2eed9624a014e5"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@sciagent/cli/MAL-2026-10718.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}