{"id":"MAL-2026-10729","summary":"Malicious code in channel-worker (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cb42c8663e71b69abd887afe5b53f3c9d57bb405dd9e8ec4954eb1bf9bb0c033)\nThe package's runtime code implements a remote command-and-control agent rather than a normal library. bin/cli.js hardcodes the endpoint https://api.channel.tunasm.art and issues POST calls with host identifiers to that endpoint via fetch. lib/command-poller.js pairs child_process execution with GET/POST loops against a remote controller, taking command IDs from responses and executing OS commands (including ping) locally. lib/cache-server.js and lib/nst-manager.js reinforce the same shape: child_process combined with outbound POST and ping invocations to remote hosts. This is a poll-execute-report agent structure — installing or running this package registers the host with the operator of api.channel.tunasm.art and executes commands returned by that server, providing persistent remote access to the machine.\n","modified":"2026-07-16T19:19:43.964253433Z","published":"2026-07-16T18:47:19Z","database_specific":{"malicious-packages-origins":[{"versions":["2.5.39"],"id":"IN-MAL-2026-010784","import_time":"2026-07-16T18:54:04.719692235Z","modified_time":"2026-07-16T18:47:19Z","sha256":"cb42c8663e71b69abd887afe5b53f3c9d57bb405dd9e8ec4954eb1bf9bb0c033","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/channel-worker/v/2.5.39"}],"affected":[{"package":{"name":"channel-worker","ecosystem":"npm","purl":"pkg:npm/channel-worker"},"versions":["2.5.39"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"818e5395c93f2f4e383056766e994351f9d7fe68","sha512_sri":"sha512-PDPrQsyBBS/Osh7YsSvjRL0vZJvwvoET4wmAJW0ZURzH6c/aHZKGWb65RYw2lviEYdPWkXN/WnK20cDZgiMooQ=="},"filename":"channel-worker-2.5.39.tgz"}],"evidence_files":[{"path":"bin/cli.js","sha256":"c782b0125d30afe17df02da574a65a4cf212fe468fe68ae799e01c8f97db9c85","tlsh":"7302a5855bfa4a3147733181956f2626341dba037184eca475dda34dafeac21e0b3dec"},{"tlsh":"6be175c76af720268aa3f26a5b0b21517225d01bb519c999fe4c53a46f8253c20f1ef8","path":"lib/cache-server.js","sha256":"6faf8a79722e37d120994a1d974a5b0ed91d313be119337017fcecb942d73d33"},{"tlsh":"9483c75b86ff10360837346e6f9b30027512e1473658cd993b6c93585f8e5288aeaff9","path":"lib/command-poller.js","sha256":"4f3a57d6b89a3cbaa41d8c06940ecf78f599d276424233fbbeaaf10c53d517a5"},{"tlsh":"4b12304ad4ff182309fb797d3adb2016322895173859dc48b68c43a81f9641cc5f6beb","path":"lib/nst-manager.js","sha256":"89cd295c97abc46eccf41e18440ab3f7e0527c24c2d0dfe22b0702c770740f12"},{"sha256":"38bf692bc5ef515830c29dd1903c38318880011ddf0f2d0ee93e94afdbfc60d3","tlsh":"ed510dc157fba334563323a49e0b52123326d107320ad998b6ee42956fd7618c66beec","path":"lib/updater.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/channel-worker/MAL-2026-10729.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}