{"id":"MAL-2026-12090","summary":"Malicious code in @wethenorth12/docker-api-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ae39aac54233ee3235e2cb94f52d5d4e182a6f16d91ac42b9d7add9bd8c00470)\nPackage advertises itself as a 'drop-in replacement for dockerode' but the main module (index.js) has no Docker functionality. On require, it collects hostname, username, home directory, platform, cwd, a timestamp, and the entire process.env, base64-encodes a JSON blob of those fields, and sends it via an HTTPS GET to api.telegram.org/bot\u003ctoken\u003e/sendMessage with chat_id=8969499041. A tmp marker file suppresses repeat sends. The wholesale process.env dump routinely carries CI/build secrets such as AWS_*, GITHUB_TOKEN, NPM_TOKEN, and other installer-owned credentials, so the beacon functions as a credential harvester. The fallback module.exports exposes unrelated crypto/wallet stubs (createWallet, generateMnemonic returning random bytes, signTransaction) and attempts to re-export dockerode if present, serving as cover for the exfiltration.\n","modified":"2026-08-05T07:20:51.940170472Z","published":"2026-08-05T06:24:56Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-013450","import_time":"2026-08-05T07:06:48.097935484Z","modified_time":"2026-08-05T06:24:56Z","sha256":"ae39aac54233ee3235e2cb94f52d5d4e182a6f16d91ac42b9d7add9bd8c00470","source":"amazon-inspector","versions":["2.0.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@wethenorth12/docker-api-client/v/2.0.2"}],"affected":[{"package":{"name":"@wethenorth12/docker-api-client","ecosystem":"npm","purl":"pkg:npm/%40wethenorth12/docker-api-client"},"versions":["2.0.2"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"272141cc67f1f59e22336592a42f610eb2bbcee25988fb10d198d4c76f741cc8959398","path":"index.js","sha256":"61b1bdbea5feaad1597373c965d6f79e991651cf98aa089a3245fc6de267fe7e"}],"package_integrity":[{"hashes":{"sha1":"7a3810614a797d76333f2ea9e85bf6146e423a9f","sha512_sri":"sha512-KFTfbjoyhHECmklOpg/uWtXkcmCh/Aqg0Dzxpn74DeGBbA+nqgnDO8fpcppqSdVnFR+buMF2QDPdtZp3aghM6A=="},"filename":"docker-api-client-2.0.2.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@wethenorth12/docker-api-client/MAL-2026-12090.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}