{"id":"MAL-2026-10894","summary":"Malicious code in exodus-checkout (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b10e41b9a87dc4927d3c4bc63b25bc1fa438cfae1bcf5f1d483204a18d5765f6)\nPackage `exodus-checkout` self-identifies as a security-research dependency-confusion proof-of-concept targeting an internal Exodus payments SDK. It mimics the internal API surface (`generateMnemonicSigningKeys`, `signCharge`, `signRefund`, `signCancelSubscription` in src/index.js), but every exported function throws — there is no functional implementation. On `npm install`, src/canary.js runs a postinstall hook that performs a DNS lookup and HTTPS GET to a hardcoded serveo SSH-tunnel host (`96e03fa6c292469a-172-245-86-254.serveousercontent.com/canary-install`), passing the package's own name and version as query parameters. No installer data (env vars, filesystem, credentials) is read or transmitted — the beacon carries only the package's own identity. Installer-side impact: any build that resolves `exodus-checkout` from public npm (whether by typo, dependency confusion, or accidental inclusion) breaks at runtime because all exports throw, and emits a one-way network signal to a researcher-controlled tunnel domain that is not Exodus infrastructure and cannot be audited by Exodus or the installer. Routing to human review: name-impersonation of a vendor's internal namespace plus an install-time outbound beacon is the dependency-confusion shape, but the absence of any data exfiltration or remote-code-execution mechanism keeps this below the active-attack threshold.\n","aliases":["GHSA-mqx8-fhj5-w597"],"modified":"2026-09-01T11:30:36.946222622Z","published":"2026-07-20T10:42:41Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-20T13:14:46.088305809Z","modified_time":"2026-07-20T10:42:41Z","sha256":"7675bbf85d1c6736952eca830341836db29b378fbda4a9466645f2ca28a0ac6c","source":"reversing-labs","versions":["99.0.0-canary.1"],"id":"RLMA-2026-05534"},{"versions":["99.0.0-canary.1"],"id":"IN-MAL-2026-012911","import_time":"2026-08-05T06:00:18.969147625Z","modified_time":"2026-08-05T05:06:51Z","sha256":"b10e41b9a87dc4927d3c4bc63b25bc1fa438cfae1bcf5f1d483204a18d5765f6","source":"amazon-inspector"},{"source":"reversing-labs","id":"RLUA-2026-06228","import_time":"2026-09-01T11:18:05.239135089Z","modified_time":"2026-08-24T16:50:58Z","sha256":"6711b73c156f43b51ac8272c2a4aec48ffc535e413f443a5f8777d6c9260d6ec"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exodus-checkout/v/99.0.0-canary.1"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mqx8-fhj5-w597"}],"affected":[{"package":{"name":"exodus-checkout","ecosystem":"npm","purl":"pkg:npm/exodus-checkout"},"versions":["99.0.0-canary.1"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"63e07d5f0961337a1d8bd441d49794213fa2560ad0fd89a60c8d521f75035348eff0c5","path":"src/index.js","sha256":"8df05b04ab1173592b08d71dea34f5998519f445526493f61ab3dd9dc0145a5a"},{"sha256":"16502b9065d4976ebb34fd49d0fb75f3cd0e64cf8d35872b419a6b6752485d51","tlsh":"37e06ffe4fd0a33a56701bc9f080a54fe707e3283085a2c1d69822a249c28f0ae218f0","path":"src/canary.js"},{"path":"README.md","sha256":"cacfc22dac62ab18a95edb6dff59d47e191b0b0dc4dc5365bf18782da02f5ac6","tlsh":"e8e0c04495e1032256f56cf966d709d06b7cf07061169da9bfcb560f6308a9ac30368e"}],"package_integrity":[{"filename":"exodus-checkout-99.0.0-canary.1.tgz","hashes":{"sha1":"95da3c4d9d5bd33667fdc643618bfc92f4b2dd01","sha512_sri":"sha512-sNpAjNExfERmXr5vgaTMV3Y2AllVKWv0CTOZ+HEIXV/OEkrTDfCEhSaVM9Q5SxSx2z7H4r2zY2AssMZYTcL5+w=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exodus-checkout/MAL-2026-10894.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}