{"id":"MAL-2026-10749","summary":"Malicious code in sync-grove (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (65248cd6e2924b6485824bcf382441e39d5e09860bc1e849aee0d6d289d184fb)\nPackage.json declares `\"postinstall\": \"node setup.js\"`, so `setup.js` runs automatically on `npm install`. The script assembles the strings `shelljs` and `exec` from base64 fragments at runtime, then fetches two plain-HTTP URLs on player.sweeprovider.org (`/getKey.php` and `/generateRandomKey.php`) whose values are stored as concatenated base64 fragments (`securityKey1`), decrypts the response with a hardcoded AES salt, and passes the resulting string to shelljs.exec on the installer's host. The package presents itself as a typosquat of `sync-exec` (\"Synchronous exec with status code support\"), and `js/syncgrove.js` mirrors the sync-exec implementation as a decoy. The combination of hardcoded remote HTTP endpoints, runtime-assembled module/method names, encrypted payload staging, and shell execution at install time is a supply-chain dropper: whatever command the attacker serves runs with the installer's privileges on `npm install`.\n","modified":"2026-07-16T19:19:59.896088189Z","published":"2026-07-16T18:35:11Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-16T18:54:00.398791815Z","modified_time":"2026-07-16T18:35:30Z","sha256":"1c57339261b245f25fe1c0a8c553fc51e054f2a3905e6c8810ae9260640141b9","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-010708"},{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-010706","import_time":"2026-07-16T18:54:00.321902303Z","modified_time":"2026-07-16T18:35:11Z","sha256":"65248cd6e2924b6485824bcf382441e39d5e09860bc1e849aee0d6d289d184fb"},{"modified_time":"2026-07-16T18:35:46Z","sha256":"f12adf46d43c2bba759fa37315f487d4343ee9e3106e94d938feedcfb7c86bdf","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-010709","import_time":"2026-07-16T18:54:00.437539846Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sync-grove/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sync-grove/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sync-grove/v/1.0.0"}],"affected":[{"package":{"name":"sync-grove","ecosystem":"npm","purl":"pkg:npm/sync-grove"},"versions":["1.0.2","1.0.1","1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"e54673928510dfff3029189614bf8b1a60b24e4f","sha512_sri":"sha512-YZvhlI+2D40LzzzTiV1E4Mx9jubANZoMOB1usjJ1pvYuUCVZWR58Atboy/+KW4njEz7wOIobZR8QgzH20lJLkg=="},"filename":"sync-grove-1.0.2.tgz"}],"evidence_files":[{"tlsh":"d821df463c3e64a283b04ad7f536e44eda1b8f0b2121c3b376dd19494f5d800ad129f0","path":"setup.js","sha256":"98b95bc28376ba79784d76d83ecb40aa422c744b71548c71d7b69f7756bb337e"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sync-grove/MAL-2026-10749.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}