{"id":"MAL-2026-10726","summary":"Malicious code in astro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (949822741657acf4a6b9f6255a2f7a080ca1cc3343e9663020c5e21ce2a6b03c)\nThis tarball is published as astro@7.1.0 but does not match the legitimate withastro/astro project (which is on the v5.x line and depends on picocolors, debug, and @astrojs/markdown-remark). The package.json declares dependencies on typosquat-shaped names on the same registry: piccolore, obug, and @astrojs/markdown-satteri. Core modules import these look-alikes unconditionally — dist/core/logger/node.js contains `import { createDebug, enable as obugEnable } from \"obug\"` and dist/cli/infra/piccolore-text-styler.js contains `import colors from \"piccolore\"` — so any `require('astro')` or CLI invocation causes those attacker-controlled packages to be resolved and executed inside the installer's node_modules tree. The version jump from the real 5.x line and the substitution of the standard utility dependencies with lookalike names indicate a registry impersonation of the astro framework, structured as a dependency-chain dropper.\n","modified":"2026-07-23T07:54:19.529025918Z","published":"2026-07-16T18:39:39Z","withdrawn":"2026-07-17T08:42:02Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["7.1.0"],"id":"IN-MAL-2026-010735","import_time":"2026-07-16T18:54:01.867712013Z","modified_time":"2026-07-16T18:39:39Z","sha256":"949822741657acf4a6b9f6255a2f7a080ca1cc3343e9663020c5e21ce2a6b03c"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/astro/v/7.1.0"}],"affected":[{"package":{"name":"astro","ecosystem":"npm","purl":"pkg:npm/astro"},"versions":["7.1.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"astro-7.1.0.tgz","hashes":{"sha1":"0646a4d822d4d3a157b58b4abb22f75316dda3ba","sha512_sri":"sha512-jXHNZXpO0HOuANLwv5uLg5WFXFmIMyDTMlokIb8sv10y8QItOFaikwrqvp6+Pe0MSqvp+aO7V1SfVriFcCEKgA=="}}],"evidence_files":[{"sha256":"8ade6533a2b7e6ee93a7cce04d3f3b56bdc3a97abf4cf1c3f247b66ef6f24773","tlsh":"74f1fd15cde98c6329840ea9b8760182b236c2474d40fa0d379916bd5f8d7df21fbb6e","path":"package.json"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/astro/MAL-2026-10726.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}