{"id":"MAL-2026-11474","summary":"Malicious code in paraglide-js (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (22f62eaf75227ca79ee8d113b790e60589d2f29204db3e6f3939e3dd3c7527cf)\nPackage name closely resembles the widely used @inlang/paraglide-js i18n library, but the declared main entry (index.js) is only a helloWorld stub. The real payload is lib/report.js and the bundled CLI install-email-research: it runs `gh api user/emails`, reads git config user.email and ~/.gitconfig, reads npm config, and gathers os.userInfo() and os.hostname(), then POSTs the collected identity data (email, username, hostname) to the hardcoded webhook https://hooks.zapier.com/hooks/catch/28124699/42vdpup/. package.json describes the package as a 'harmless security research payload created by Capsule Security'; the self-label does not change the behavior — installers arriving via the look-alike name have their developer identity exfiltrated to a third-party endpoint. A postinstall consent gate is present, but the shipped CLI is the mechanism that captures the Y/N and performs the send.\n\n## Source: ghsa-malware (311880366b1380bc5c79df504252810120f8ca8cdd0e64c9ff0001e080da34e3)\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.\n","aliases":["GHSA-433p-gj42-fh44"],"modified":"2026-08-04T23:05:23.195225583Z","published":"2026-07-31T22:00:03Z","database_specific":{"malicious-packages-origins":[{"source":"ghsa-malware","versions":["1.0.1"],"id":"GHSA-433p-gj42-fh44","import_time":"2026-08-02T22:41:04.721577Z","modified_time":"2026-07-31T22:00:04Z","sha256":"311880366b1380bc5c79df504252810120f8ca8cdd0e64c9ff0001e080da34e3"},{"import_time":"2026-08-04T22:30:08.722146765Z","modified_time":"2026-08-04T21:58:33Z","sha256":"22f62eaf75227ca79ee8d113b790e60589d2f29204db3e6f3939e3dd3c7527cf","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-011280"}]},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-433p-gj42-fh44"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/paraglide-js/v/1.0.1"}],"affected":[{"package":{"name":"paraglide-js","ecosystem":"npm","purl":"pkg:npm/paraglide-js"},"versions":["1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/paraglide-js/MAL-2026-11474.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"lib/report.js","sha256":"0046a51ccd82a86175301dc0bf8c358ebf9ca7673ae1270024bcb104f16080b9","tlsh":"adc1c69b2afa11341e6365b8f74f10327952e2173e09ec60b8bc531d0f87e6845b79da"},{"sha256":"6b30e889b097333531fe3dbea74032ef0cfc31a8629182a39c1a4f0d8e7c8682","tlsh":"dff0a320d9441277fcc825979c32d10f66516c0d11193d29277300dce24dfb9587b6d9","path":"package.json"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}