{"id":"MAL-2026-10769","summary":"Malicious code in easyway2 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fcfc1bc035f5239e384f9e32be4fc53cdffe065920da7c6181e42757d6b41195)\nOn npm install, the package's postinstall hook executes index.js, which POSTs the installer's full process.env, OS username, and current working directory to http://crabbing-thong-overhung.ngrok-free.dev/v1/init over plain HTTP. It then re-spawns itself as a detached, stdio-ignored background process (node index.js bg) that persists beyond npm install completion and recursively walks the filesystem from the root, reading.env,.conf,.json,.yaml,.yml,.sql,.log,.txt,.js, and dotfiles. Matches against JWT and mongodb/postgres/mysql/redis/amqp connection-string regexes are POSTed with the hostname to /v1/leak on the same ngrok tunnel. The ngrok-free.dev destination is an ephemeral, attacker-controlled ingress; the plain-HTTP transport and detached background scan are consistent with credential-harvesting malware.\n\n## Source: ossf-package-analysis (b70fe150bb8d389d4b3f437dff96763448359cafed12db8139236f3d40b88565)\nThe OpenSSF Package Analysis project identified 'easyway2' @ 1.0.3 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-07-28T14:36:56.122910763Z","published":"2026-07-17T12:44:58Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-17T12:44:58Z","versions":["1.0.3"],"source":"ossf-package-analysis","sha256":"b70fe150bb8d389d4b3f437dff96763448359cafed12db8139236f3d40b88565","import_time":"2026-07-17T12:58:02.018368476Z"},{"sha256":"dff64fea0cd0fc61895597193439279782028def9d61a53fa870e90a4cfb7a50","import_time":"2026-07-17T14:36:10.405326207Z","modified_time":"2026-07-17T14:10:44Z","versions":["1.0.7"],"source":"ossf-package-analysis"},{"import_time":"2026-07-28T14:19:59.342286115Z","id":"IN-MAL-2026-010925","modified_time":"2026-07-28T13:37:17Z","versions":["1.0.11"],"source":"amazon-inspector","sha256":"2aed763a51b55d0830b211bb892f32531304b1f06b17109a8e82d5fba41d9c7a"},{"id":"IN-MAL-2026-010930","modified_time":"2026-07-28T13:38:03Z","versions":["1.0.0"],"source":"amazon-inspector","sha256":"401380d5c2d7140f8776cbcc91a659162768719fcf84f8a4035072e5de59a9d6","import_time":"2026-07-28T14:19:59.57556823Z"},{"versions":["1.0.8"],"source":"amazon-inspector","sha256":"7f826eb21c09c1992cb7181e603af9580b86c45119c7e1c8be2f700897a97f52","import_time":"2026-07-28T14:19:58.636907404Z","id":"IN-MAL-2026-010910","modified_time":"2026-07-28T13:35:00Z"},{"import_time":"2026-07-28T14:19:59.158721787Z","id":"IN-MAL-2026-010921","modified_time":"2026-07-28T13:36:41Z","versions":["1.0.3"],"source":"amazon-inspector","sha256":"a56bd768435fd324b7b5d037f8cac9bab5d1342c0d312c6647ff794c2ec66ef8"},{"id":"IN-MAL-2026-010926","modified_time":"2026-07-28T13:37:27Z","versions":["1.0.2"],"source":"amazon-inspector","sha256":"bd2f138e2aa5d09f80180c3818534c7bdbc77cb9346f27ef83e3ad9fe0466004","import_time":"2026-07-28T14:19:59.369761235Z"},{"import_time":"2026-07-28T14:19:59.12124985Z","id":"IN-MAL-2026-010920","modified_time":"2026-07-28T13:36:32Z","versions":["1.0.6"],"source":"amazon-inspector","sha256":"d6c90ac4a7a2227ca95b892b15beb34a88970aaa7729fd1584fcaa48a000c285"},{"modified_time":"2026-07-28T13:36:49Z","versions":["1.0.5"],"source":"amazon-inspector","sha256":"4a633182d940458c870c82422e6e43cedbcc01f9928eaac00f982798bc569e98","import_time":"2026-07-28T14:19:59.235646839Z","id":"IN-MAL-2026-010922"},{"sha256":"975cdc72d222f763e149ad095c127af814ec344161108f30d967153e24816801","import_time":"2026-07-28T14:19:59.410539572Z","id":"IN-MAL-2026-010927","modified_time":"2026-07-28T13:37:35Z","versions":["1.0.10"],"source":"amazon-inspector"},{"versions":["1.0.1"],"source":"amazon-inspector","sha256":"c88c1ee649c0d3dec8a0d0326727f44bfe35f72f5537e988060be3157edc2b35","import_time":"2026-07-28T14:19:59.519229867Z","id":"IN-MAL-2026-010929","modified_time":"2026-07-28T13:37:53Z"},{"import_time":"2026-07-28T14:19:58.513102386Z","id":"IN-MAL-2026-010907","modified_time":"2026-07-28T13:34:35Z","versions":["1.0.9"],"source":"amazon-inspector","sha256":"db5048ba840343b2dbeaf43ba302c6f36e2704b5a9ad510e656164d876c688c6"},{"sha256":"fcfc1bc035f5239e384f9e32be4fc53cdffe065920da7c6181e42757d6b41195","import_time":"2026-07-28T14:19:58.774515655Z","id":"IN-MAL-2026-010913","modified_time":"2026-07-28T13:35:30Z","versions":["1.0.7"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.11"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/easyway2/v/1.0.7"}],"affected":[{"package":{"name":"easyway2","ecosystem":"npm","purl":"pkg:npm/easyway2"},"versions":["1.0.3","1.0.7","1.0.11","1.0.0","1.0.8","1.0.2","1.0.6","1.0.5","1.0.10","1.0.1","1.0.9"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/easyway2/MAL-2026-10769.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"369e4ced330a5ced4d0d98ebc9f01f0258af3461f3c162b38e46305b20b5b358","tlsh":"6bf00ce08005d46f9fc503a67ee28005d07a3a0aa103ac14da214ad72bcc26abcb8384"}],"package_integrity":[{"filename":"easyway2-1.0.11.tgz","hashes":{"sha512_sri":"sha512-Bqtm2QwzecJ1MDI5FZq0SjxUJ+Fv2LXcvuUf5UkZZLYFBcTJ2zB/9IrZc+GNzOMALNl+VbBb5gzYZbet2MdX+Q==","sha1":"261bf2163d982bcce435c04646c371e832e3c9fe"}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}