{"id":"MAL-2026-11072","summary":"Malicious code in wsh4_edu (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0757eee7b6324baca2e2b28261c7ff072c60d578c827a14c1fa54f690b1cd53a)\nThe package's postinstall hook runs index.js, which POSTs the installer's absolute filesystem path (via __filename with sendFullPath: true), Node.js version, platform, and architecture to a hardcoded Discord webhook at discord.com/api/webhooks/1530599209269465319/. The same beacon also fires when the module is required, since index.js is the package main. The absolute path typically embeds the local username and home directory, giving the operator of the webhook a host/identity fingerprint of every machine that installs the package. The webhook URL is split across two string literals and concatenated at call time to evade casual string scanning, and the destination is not caller-configurable. The package name and README self-describe as a typo/beacon experiment.\n\n## Source: ossf-package-analysis (e68d4c62ae8440581c4400e1cdacb7877912eb23610e273432d18cea61574785)\nThe OpenSSF Package Analysis project identified 'wsh4_edu' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-08-04T23:05:48.290400414Z","published":"2026-07-25T16:00:59Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-25T16:00:59Z","sha256":"e68d4c62ae8440581c4400e1cdacb7877912eb23610e273432d18cea61574785","source":"ossf-package-analysis","versions":["1.0.0"],"import_time":"2026-07-27T01:42:44.001805577Z"},{"versions":["1.0.0"],"id":"IN-MAL-2026-011286","import_time":"2026-08-04T22:30:09.012734888Z","modified_time":"2026-08-04T21:59:29Z","sha256":"0757eee7b6324baca2e2b28261c7ff072c60d578c827a14c1fa54f690b1cd53a","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wsh4_edu/v/1.0.0"}],"affected":[{"package":{"name":"wsh4_edu","ecosystem":"npm","purl":"pkg:npm/wsh4_edu"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"wsh4_edu-1.0.0.tgz","hashes":{"sha1":"2a2859885ffde7e7def6bbd59f776f9549438003","sha512_sri":"sha512-g+ocCAOI14yj2nGBbFAWBAkQIK+0jfZ67DTSe62cNlMkofj1hcjfSDEXruu0yUNKexIk/pSsT67ivafbmjwPSg=="}}],"evidence_files":[{"path":"index.js","sha256":"1ba5b8478d28998c0247fc7f00c236e29a12dcec1fb5dc5ca507933918306c4b","tlsh":"9861438a96f022210b73f3d4614bc12bbb2985132a4ecd45f64c57b41fce67dd4e56e8"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wsh4_edu/MAL-2026-11072.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}