{"id":"MAL-2026-10995","summary":"Malicious code in habingeer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (716d1a3d9969396f8ca204c03d403552bb4a990c1bfdb4a2ab05dff5afb93748)\npackage.json declares `postinstall: node test.js`, which auto-runs on `npm install` and invokes two functions from index.js. The first recursively walks the install directory for `id.json` (Solana keypair), `config.toml`/`Config.toml`, `env`, and `.env` files and POSTs each file body, prefixed with the installer's username, to http://170.205.31.203:3000/api/v1. The second fetches an SSH public key from http://170.205.31.203:3001/api/ssh-key and, on Linux, appends it to `~/.ssh/authorized_keys`, then executes `sudo ufw enable` and `sudo ufw allow 22/tcp` to keep inbound SSH reachable — granting the operator of that IP persistent interactive SSH access to the host. The same function then pulls scan/block patterns from the C2, enumerates `os.homedir()` on Unix or every logical drive on Windows (via `wmic logicaldisk get name` / PowerShell `Get-Volume`), and batch-uploads matching files with username/platform metadata via multipart POST to http://170.205.31.203:3001/api/v1. All three behaviors fire on install with no user interaction.\n","modified":"2026-07-23T07:51:35.099571363Z","published":"2026-07-22T20:27:26Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-22T20:31:07.980388782Z","modified_time":"2026-07-22T20:27:26Z","sha256":"716d1a3d9969396f8ca204c03d403552bb4a990c1bfdb4a2ab05dff5afb93748","source":"amazon-inspector","versions":["2.1.6"],"id":"IN-MAL-2026-010803"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/habingeer/v/2.1.6"}],"affected":[{"package":{"name":"habingeer","ecosystem":"npm","purl":"pkg:npm/habingeer"},"versions":["2.1.6"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/habingeer/MAL-2026-10995.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"d986a2e0a9eb3fc3781e166ff6b700e0d38249a6c9649982243c3754671f42d9","tlsh":"ef02934ca6fb2a2183b371ac468f1415b59ac0033949cd81b2cc97546f8f93d65f6ede"},{"tlsh":"2ef0ed27ce188e6318f135a8287c0617f281932f0100880f35fd264c4fb6223008af1e","path":"package.json","sha256":"f277e4e6f6401b293a085c0ca10c6b02ea1db907af3679d4a09f91cb709ba562"}],"package_integrity":[{"filename":"habingeer-2.1.6.tgz","hashes":{"sha1":"bae6a9fbf8ed4bcf26875a0b7c6c3de6d50fa25b","sha512_sri":"sha512-Ajfr/BDj/xi48VqU2JZJMth4SA0RxfsWIGU2ES3e+XIJn3qSbsI43JFzskwcYvUm0wyM54X1dBwCbQW2f32XHg=="}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}