{"id":"MAL-2026-10719","summary":"Malicious code in @thepayulink/server (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f0f04014bd624dc0712b8bfb78c53832ef18bf6a178d462b1959df9a8b81ec94)\nThe CommonJS bundle loaded by `require('@thepayulink/server')` (dist/payulink-server.cjs) hardcodes `apiBase` to `https://eliteyatra.vip` as the default destination and attaches the caller-supplied `keySecret` as an `Authorization: Bearer` header on outbound order/fetch requests. That destination is unrelated to the package's declared publisher: package.json homepage and README point to `payulink.io`, and the ESM source at src/index.js targets `https://payulink.io/api` using Basic auth with `pl_live_` keys and paise, whereas the shipped CJS dist targets `eliteyatra.vip` using Bearer auth with `pl_sk_` keys and rupees. The dist bundle is therefore not a build of the shipped src — it is a different SDK glued under the same package name that redirects the caller's PayuLink secret and order data to an author-controlled domain the documented API never references. Any consumer using the documented CommonJS default silently exposes their payment gateway secret key and transaction data to eliteyatra.vip.\n","modified":"2026-07-16T19:19:38.087505209Z","published":"2026-07-16T18:45:45Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["2.0.0"],"id":"IN-MAL-2026-010774","import_time":"2026-07-16T18:54:04.060583826Z","modified_time":"2026-07-16T18:45:45Z","sha256":"f0f04014bd624dc0712b8bfb78c53832ef18bf6a178d462b1959df9a8b81ec94"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@thepayulink/server/v/2.0.0"}],"affected":[{"package":{"name":"@thepayulink/server","ecosystem":"npm","purl":"pkg:npm/%40thepayulink/server"},"versions":["2.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"7afbd49ce02714be62eea2785d0f1c1a8e9561b14ac934f25004e326b50caeae","tlsh":"9fe1820b31f2903389a290a77b278916ef65555664c98864b6dc82fc2fcd570cae8fe1","path":"dist/payulink-server.cjs"}],"package_integrity":[{"filename":"server-2.0.0.tgz","hashes":{"sha512_sri":"sha512-io+WcufgaqnGrm5T3V1eA8A9/mfLl4DdBrxnZfl7piiuC73Pey/cWm7f7oVhb6ABHazui5p2Fb4hdRxFuUNIzg==","sha1":"671a99d9a901d3198543baa0673ba97098301de8"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@thepayulink/server/MAL-2026-10719.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}