{"id":"MAL-2026-11071","summary":"Malicious code in whs4_eud (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6be47b29c887fd54b5cffc8789278f3ea7987b12d618e89c540e5670edea12b5)\nwhs4_eud@1.0.1 declares a postinstall lifecycle script (`node index.js`) that fires unconditionally on `npm install`. On execution, index.js POSTs installer-side host information — the absolute path of the install location (which embeds the user's home directory), Node.js version, and platform/architecture — to a hardcoded Discord webhook under discord.com/api/webhooks/1530599209269465319/. The webhook URL is assembled by concatenating two string literals at runtime rather than appearing as a single literal, a light obfuscation of the exfiltration destination. The package name and layout are consistent with a dependency-confusion / typosquat beacon whose only functional behavior is to notify the author when an install occurs and to disclose where.\n\n## Source: ossf-package-analysis (d906ecaf9f2ede0a31c6966b9d8402f4c80e57fb72eae7f9dfa1b3a7c583b8d4)\nThe OpenSSF Package Analysis project identified 'whs4_eud' @ 1.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-08-11T18:00:11.602667768Z","published":"2026-07-25T15:55:34Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"import_time":"2026-07-27T01:42:44.1209829Z","modified_time":"2026-07-25T15:55:34Z","sha256":"d906ecaf9f2ede0a31c6966b9d8402f4c80e57fb72eae7f9dfa1b3a7c583b8d4","source":"ossf-package-analysis"},{"id":"IN-MAL-2026-011261","import_time":"2026-08-04T22:30:07.961552055Z","modified_time":"2026-08-04T21:55:43Z","sha256":"6be47b29c887fd54b5cffc8789278f3ea7987b12d618e89c540e5670edea12b5","source":"amazon-inspector","versions":["1.0.1"]},{"sha256":"f8dcbecbaf2392f7cd7720244800fde67c971fa7fa34fb8cf21d61c580dd4713","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-017376","import_time":"2026-08-11T17:51:59.251904999Z","modified_time":"2026-08-11T17:24:19Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/whs4_eud/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/whs4_eud/v/1.0.0"}],"affected":[{"package":{"name":"whs4_eud","ecosystem":"npm","purl":"pkg:npm/whs4_eud"},"versions":["1.0.1","1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"5cc9cd2e5a872d5b641b6a1c4bf5e201468b693e6eb9cc4053e4f9296ab52f20","tlsh":"0761518a96f022210ba3f3d4204bc12bbb2985132a0ecd45f64c47b41fce67dd4e52e8","path":"index.js"}],"package_integrity":[{"hashes":{"sha1":"8553c23b13668bdb44198b8b0fc6d836b7856c5f","sha512_sri":"sha512-m+Ga9ZEpPNwJbjyxLQtk2xzdtNrNPoyPw+cZSa8jXd8qPr46mD5UIg9pQFq9rRZfSdwEcPA28mmvB1/ZJ1lk/w=="},"filename":"whs4_eud-1.0.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/whs4_eud/MAL-2026-11071.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}