{"id":"MAL-2026-10893","summary":"Malicious code in ecto-cargo-wk1tm59a (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29)\nPackage ecto-cargo-wk1tm59a@99.0.0 exhibits several contextual red flags worth human review: a randomized-suffix name pattern (`-wk1tm59a`) typical of disposable/throwaway publishes, an inflated `99.0.0` version typical of dependency-confusion / proof-of-concept publishes, and only 3 files in the tarball. Automated content inspection of the package's code did not produce a usable trace, but the content was non-trivial enough that an automated description could not be produced. No specific attacker domain, exfiltration endpoint, or install-time fetch-and-execute behavior has been concretely identified from the available evidence, so a public block verdict is not justified, but the combination of disposable-name shape, `99.0.0` version inflation, and untraced contents warrants human inspection before this package is trusted.\n","aliases":["GHSA-wx6c-2wgg-hcwq"],"modified":"2026-09-01T11:30:36.824020662Z","published":"2026-07-20T10:40:54Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","versions":["99.0.0"],"id":"RLMA-2026-05530","import_time":"2026-07-20T13:14:45.643678329Z","modified_time":"2026-07-20T10:40:54Z","sha256":"4d658031a727ec8ae264cb396f9e130d1c4cb8c28f803b2275bb45a09fb01507"},{"versions":["99.0.0"],"id":"IN-MAL-2026-012955","import_time":"2026-08-05T06:00:24.08053767Z","modified_time":"2026-08-05T05:13:06Z","sha256":"ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29","source":"amazon-inspector"},{"import_time":"2026-09-01T11:18:02.141968377Z","modified_time":"2026-08-24T16:48:14Z","sha256":"e53b8340ac7ffea00b9252f6026d200b5552e4c5a35aa338a09b00fc2812c70f","source":"reversing-labs","id":"RLUA-2026-06181"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ecto-cargo-wk1tm59a/v/99.0.0"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-wx6c-2wgg-hcwq"}],"affected":[{"package":{"name":"ecto-cargo-wk1tm59a","ecosystem":"npm","purl":"pkg:npm/ecto-cargo-wk1tm59a"},"versions":["99.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-l5wZqLuVciZB1UWmCFkeiqvPN6wwoqGcEgWC9u6VT+LPqYC0E9bLba3jt/da5aOGZLwQoBYxZZKozCrnJ2/7vA==","sha1":"b1da901e3c4763b49cf7e736a21c76c44c0446d2"},"filename":"ecto-cargo-wk1tm59a-99.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ecto-cargo-wk1tm59a/MAL-2026-10893.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}