{"id":"MAL-2026-11119","summary":"Malicious code in json-to-table-util (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2317bf7f973ca611fdd2215509ae94c302f868ae9fb5c5f00de0b6bd13fe3bc4)\npostinstall.js runs automatically on `npm install` and executes a shell pipeline via child_process.exec that collects hostname, user, working directory, uname, container/cgroup indicators, process tree, network info (/etc/resolv.conf, IPs), GitHub Actions CI variables (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, RUNNER_NAME), and the entire process environment via `env` (filtering only npm_* noise). It also probes AWS IMDS at 169.254.169.254 and Tencent Cloud metadata at metadata.tencentyun.com to fingerprint cloud infrastructure. The aggregated output is base64-encoded and sent over plain HTTP via curl GET to the hardcoded Burp Collaborator subdomain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com/z?d=\u003cbase64\u003e. On CI runners this captures any secrets exported to the environment (cloud keys, GITHUB_TOKEN, tokens injected into the job).\n\n## Source: ossf-package-analysis (63ee08885a126855fbc96dbbb6f8c4ef903d9dc8f2cb02fe0fa178a7db1ed904)\nThe OpenSSF Package Analysis project identified 'json-to-table-util' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-04T22:05:07.244939264Z","published":"2026-07-28T08:16:24Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-28T08:16:24Z","sha256":"63ee08885a126855fbc96dbbb6f8c4ef903d9dc8f2cb02fe0fa178a7db1ed904","source":"ossf-package-analysis","versions":["1.0.0"],"import_time":"2026-07-28T08:22:36.503847965Z"},{"id":"IN-MAL-2026-011011","import_time":"2026-08-04T21:33:13.574735302Z","modified_time":"2026-08-04T21:19:28Z","sha256":"2317bf7f973ca611fdd2215509ae94c302f868ae9fb5c5f00de0b6bd13fe3bc4","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/json-to-table-util/v/1.0.0"}],"affected":[{"package":{"name":"json-to-table-util","ecosystem":"npm","purl":"pkg:npm/json-to-table-util"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"8931fbf8b56ded72304dc5f8b75d14053846eaeb58e4ff74281b8875008e48420a9136","path":"postinstall.js","sha256":"5826f6884581fbfa40d0793ff4c4b6f3b4e5e0a704bfd87bf7c4e3ec274b2ec9"}],"package_integrity":[{"filename":"json-to-table-util-1.0.0.tgz","hashes":{"sha1":"5ec923bba2abdf09fa5e9d15e4f437614bee893b","sha512_sri":"sha512-T7Hz5mLbDSO+t/cSXFakbg7YT2RPJJuoGe3azZm32nc6niI/bOR+sLY7zbLpq+UtEvwP6unV1CLzK1pFME7+vg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/json-to-table-util/MAL-2026-11119.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}