{"id":"MAL-2026-12315","summary":"Malicious code in @cryptosrvc/no-brainer-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7955af180bb00f4f97b5dee0c7020f9e43f4c35aa84c5ef5446dd95646eb333b)\nOn npm install, the package's postinstall script (dist/recon.js) collects installer-side host reconnaissance — hostname, username, SUDO_USER, home directory, cwd, network interfaces including internal IPs, DNS domain via dnsdomainname, and npm lifecycle context — and enumerates process.env, filtering the key names against a regex targeting AWS, GCP, AZURE, NPM, NODE_AUTH, DOCKER, KUBE, VAULT, TOKEN, SECRET, KEY, PASS, CRED, GITHUB, GITLAB, and SSH. Both the full env-name list and the credential-shaped subset are serialized and POSTed as JSON over plain HTTP to hardcoded bare IP 138.68.108.20:80/cb, with a `npm-install-telemetry/1.0` User-Agent and an inline comment framing the payload as 'NON-SENSITIVE telemetry only' despite including sudo_user, internal network layout, and credential env-var name inventory. Behavior fires automatically as a postinstall lifecycle hook.\n","modified":"2026-08-05T13:35:08.341450639Z","published":"2026-08-05T13:01:29Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.18"],"id":"IN-MAL-2026-014852","import_time":"2026-08-05T13:08:51.129287555Z","modified_time":"2026-08-05T13:01:29Z","sha256":"7955af180bb00f4f97b5dee0c7020f9e43f4c35aa84c5ef5446dd95646eb333b"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@cryptosrvc/no-brainer-sdk/v/1.0.18"}],"affected":[{"package":{"name":"@cryptosrvc/no-brainer-sdk","ecosystem":"npm","purl":"pkg:npm/%40cryptosrvc/no-brainer-sdk"},"versions":["1.0.18"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"cf516a4fddaeeec18aa158b24503fb532cb928411b6720ee31516e9b00510057","tlsh":"0c51845612b92532229256a9366b10013233f0273f85f9d8bddc13611fcd42d41f6bed","path":"dist/recon.js"}],"package_integrity":[{"filename":"no-brainer-sdk-1.0.18.tgz","hashes":{"sha1":"990c558d941ce3becbf0848a0df7bff8ea19bb3b","sha512_sri":"sha512-5PB+n/9sHEpyUt+9swY8npyI6cjBzKej1kWyIS3rJUIuTCtTFusYtWRsNPvjbkJjOCduNNSs1/1tfwCokVbJ9A=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@cryptosrvc/no-brainer-sdk/MAL-2026-12315.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}