{"id":"MAL-2026-11537","summary":"Malicious code in discord-vibegrations-api-natives (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (9cb64ecc29aa68ec4659bab280f4ffd2c3de889cc966c0974f85b0c488edc603)\nOn npm install, the package's postinstall.js opens a TCP socket to 5.tcp.eu.ngrok.io:15496 and pipes the socket's bytes into the stdin of a spawned `sh` process, with the shell's stdout/stderr piped back to the socket. The package.json declares `\"postinstall\": \"node postinstall.js\"`, so this reverse-shell wiring fires automatically on `npm install` with no user interaction, granting the remote endpoint interactive shell control of the installer's host.\n","modified":"2026-08-04T23:05:01.253865113Z","published":"2026-08-04T22:05:57Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-04T22:05:57Z","sha256":"9cb64ecc29aa68ec4659bab280f4ffd2c3de889cc966c0974f85b0c488edc603","source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-011330","import_time":"2026-08-04T22:30:11.219393001Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/discord-vibegrations-api-natives/v/1.0.5"}],"affected":[{"package":{"name":"discord-vibegrations-api-natives","ecosystem":"npm","purl":"pkg:npm/discord-vibegrations-api-natives"},"versions":["1.0.5"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"578cb8fae781531d5a38c08482e8b2cd2ad4d20f","sha512_sri":"sha512-qgX99Xbl1OfmnhkbWmVMmd/wHts/2pAf60iqIaqRjx/7EkyZ7TgEmnHC63D+ZpPzYIOjeMHAU/FJaVO1vr8dbg=="},"filename":"discord-vibegrations-api-natives-1.0.5.tgz"}],"evidence_files":[{"path":"postinstall.js","sha256":"a8bd49f0015fe1138b6476a7ae99a2aa76c5c53b3406f4d91ad0dbbfac455417","tlsh":"5be0d88964b724ba217331aace3fc0173373002b3603e159750d8cd80f9958c6b6eae1"},{"sha256":"fef693cce02efa542ea406815113ad58b319b7f474945ae0588014879590b639","tlsh":"0ae0c2201a62963325c506260d168186a670de5f1404780c13df586cc2cf6776afb32f","path":"package.json"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/discord-vibegrations-api-natives/MAL-2026-11537.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}