{"id":"MAL-2026-12326","summary":"Malicious code in @offa/offa-uwk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3a04489d4763fb48f4c5bc4ea7e99802b21a412ba55900ae7bf411070e2a42d8)\npackage.json declares a postinstall hook that runs index.js. On install, index.js collects os.hostname(), os.userInfo().username, process.cwd(), and the entire process.env object, then POSTs the JSON payload via https.request to the hardcoded endpoint https://e6b10849-38dc-4280-a8e3-72ab39cfaf65.webhook.site/collect. Dumping the whole process environment on install ships every environment variable on the installer's machine — commonly containing AWS/GCP/GitHub/npm and other tokens — to an anonymous attacker-controlled webhook. A preinstall hook additionally writes a marker file to the hardcoded absolute path /home/OFFA/flag.\n","modified":"2026-09-01T11:30:32.853132509Z","published":"2026-08-05T12:57:06Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["999.0.1"],"id":"IN-MAL-2026-014821","import_time":"2026-08-05T13:08:49.068059338Z","modified_time":"2026-08-05T12:57:06Z","sha256":"321b84802e64efd2edf01527613d8d37aeaa63ee37505c59bf48a94f5ec88aed"},{"versions":["999.0.0"],"id":"IN-MAL-2026-014853","import_time":"2026-08-05T13:08:51.179695274Z","modified_time":"2026-08-05T13:01:38Z","sha256":"3a04489d4763fb48f4c5bc4ea7e99802b21a412ba55900ae7bf411070e2a42d8","source":"amazon-inspector"},{"modified_time":"2026-08-24T16:26:44Z","sha256":"b723c56d5e136730cbcaf2fe69f14c7a114d0d6962c126994517a7a926f7e98e","source":"reversing-labs","versions":["999.0.0"],"id":"RLMA-2026-05891","import_time":"2026-09-01T11:17:25.283372947Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@offa/offa-uwk/v/999.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@offa/offa-uwk/v/999.0.0"}],"affected":[{"package":{"name":"@offa/offa-uwk","ecosystem":"npm","purl":"pkg:npm/%40offa/offa-uwk"},"versions":["999.0.1","999.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"2cf6459022c35a8cf62f708f2e0963986fd5d73b","sha512_sri":"sha512-vBeTNqxieTsWkFSFj4CDPtalD3+5d7aRd+DD0NEiU6QrMhnhdUDAWMMm/66AXcqSL2owJfru5PxbXLDYjPIluw=="},"filename":"offa-uwk-999.0.1.tgz"}],"evidence_files":[{"sha256":"1a59154c39015bd7a0b6035429c3dd17c663df42a7ab239b9a78c9eaf6b12216","tlsh":"131161f0457152e06af740c0a042780e6663e9037207f814f99d83555fc8afc45a2af4","path":"index.js"},{"path":"package.json","sha256":"f0e49be9373e4132c4bb9426c551f2bbff24278865eafb1b0611707e5334bbf7","tlsh":"40d0c2304e10952369c047a60c27a4467aa10e1740107c44a7e7122845dabbf44ff33e"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@offa/offa-uwk/MAL-2026-12326.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}