{"id":"MAL-2026-11122","summary":"Malicious code in @crbrc/xbt (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (179d74e089794cb517fcb4030021310137bedcc72f0ef49362b4ce1724cb5ac3)\ndist/index.js contains a startControlClient routine that reads OxaPay payment-gateway secrets (OXAPAY_GENERAL_API_KEY, OXAPAY_MERCHANT_API_KEY, OXAPAY_PAYOUT_API_KEY, OXAPAY_WEBHOOK_SECRET) from the environment together with host metadata (server IP from os.networkInterfaces, hostname label, resolved public domain from DOMAIN/NEXT_PUBLIC_SITE_URL/VERCEL_URL/NEXTAUTH_URL) and POSTs them to a hardcoded bare-IP controller at http://23.160.168.168:4141/register over plain HTTP. The same module opens a WebSocket to ws://23.160.168.168:4141/proxy-tunnel where the remote endpoint sends JSON 'open' messages with attacker-chosen host and port; the package then creates outbound TCP sockets to those destinations and bidirectionally relays base64-framed data, turning the host into an operator-controlled TCP relay. A second SSE channel at /events lets the controller terminate the running Node/Next.js process on a 'stop' event. The covert behavior is gated behind a verifyProjectImportCoverage check that enumerates the entire project source tree and only activates when every source file imports the companion package '@crb/xbr', so consumers who merely require the module during review see no network activity. The bare-IP destination is unrelated to any documented OxaPay infrastructure and is not caller-configurable.\n","modified":"2026-07-28T14:37:17.523334963Z","published":"2026-07-28T13:40:07Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-010949","import_time":"2026-07-28T14:20:00.752807769Z","modified_time":"2026-07-28T13:40:37Z","sha256":"058c590aee7b5df39e33a28dc448cec5cb2581e444824e0189546cdbb25df74d","source":"amazon-inspector","versions":["1.1.2"]},{"import_time":"2026-07-28T14:20:00.5553725Z","modified_time":"2026-07-28T13:40:07Z","sha256":"179d74e089794cb517fcb4030021310137bedcc72f0ef49362b4ce1724cb5ac3","source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-010945"},{"versions":["1.2.1"],"id":"IN-MAL-2026-010947","import_time":"2026-07-28T14:20:00.650502785Z","modified_time":"2026-07-28T13:40:24Z","sha256":"2c1ddda520378b6da51e744d1836d5e42ac1742beb6ea962140f5ab0252590ed","source":"amazon-inspector"},{"import_time":"2026-07-28T14:20:00.709052368Z","modified_time":"2026-07-28T13:40:31Z","sha256":"4ac96741026b669e8078c6b1b72f7e63fc14d1bed42a753cca659033df7cd515","source":"amazon-inspector","versions":["1.1.3"],"id":"IN-MAL-2026-010948"},{"versions":["1.1.4"],"id":"IN-MAL-2026-010951","import_time":"2026-07-28T14:20:01.044403257Z","modified_time":"2026-07-28T13:40:50Z","sha256":"968f26302e16e25cfe61a948b2020970c63f2e71aebb345ba19e801dcc950b19","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-010946","import_time":"2026-07-28T14:20:00.600972625Z","modified_time":"2026-07-28T13:40:14Z","sha256":"d26fb97a854e1338f2d0ec760231097de54f63a34fcbd9a2d8e47f73d5b4b8f3"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@crbrc/xbt/v/1.1.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@crbrc/xbt/v/1.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@crbrc/xbt/v/1.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@crbrc/xbt/v/1.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@crbrc/xbt/v/1.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@crbrc/xbt/v/1.1.0"}],"affected":[{"package":{"name":"@crbrc/xbt","ecosystem":"npm","purl":"pkg:npm/%40crbrc/xbt"},"versions":["1.1.2","1.1.1","1.2.1","1.1.3","1.1.4","1.1.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@crbrc/xbt/MAL-2026-11122.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"xbt-1.1.2.tgz","hashes":{"sha1":"8cb29be9028b0c821251ee5037ec470ebeee0ec9","sha512_sri":"sha512-dCl3YkjaKpskfWHMDaD0TIJdT9x1hg5iPrCcLH1czw3yHKJKCAsT1kf8Y9Xh0wPMScT6GMT7uZ8sEihShkr8tA=="}}],"evidence_files":[{"path":"dist/index.js","sha256":"b19241178eaf8c71a41893e0f24061fe994ea95f628e129b58f0bc187f73c189","tlsh":"76826549a9f3292446a3349da75b44167638e0033a0ccd18bbac93917f7a179d6f37ce"},{"tlsh":"39c08c92e3961320c450048c620aea95220522a4aa1a408adcfe9a88106a148f4a35e2","path":"src/config.ts","sha256":"090409429cda6389ca39bdca294d238fb7c14b585cd53703e89b3956c4930539"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}