{"id":"MAL-2026-12416","summary":"Malicious code in poly-custom-api (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a3263a9e2a986068fafa530a8e6862f9ba41cad05ecbd5b7b91752ca1c5af0c6)\nThe default export getPlugin in index.js constructs an HTTPS URL from split constants pointing at the bare IP 46.183.25.232:45000/icons/108, fetches the response, and passes the response field data.credits to new Function(...) with require, module, exports, process, Buffer, and global injected as parameters. Any caller invoking the exported function grants the remote endpoint arbitrary code execution in the Node.js process with full host privileges. The endpoint is disguised with icon/CDN vocabulary (iconDomain, font-awesome/svgs/brands, a 'bearrtoken' field literal 'logo') and an unused IconProvider map, while the package advertises itself as a 'custom API library' — the icon framing is cover for the fetch-and-eval path. The payload is mutable, unpinned, unauthenticated, and served over a bare-IP host unrelated to any legitimate publisher infrastructure.\n","modified":"2026-08-05T13:35:45.342268443Z","published":"2026-08-05T13:01:01Z","database_specific":{"malicious-packages-origins":[{"sha256":"a3263a9e2a986068fafa530a8e6862f9ba41cad05ecbd5b7b91752ca1c5af0c6","source":"amazon-inspector","versions":["5.3.1"],"id":"IN-MAL-2026-014848","import_time":"2026-08-05T13:08:50.870521254Z","modified_time":"2026-08-05T13:01:01Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/poly-custom-api/v/5.3.1"}],"affected":[{"package":{"name":"poly-custom-api","ecosystem":"npm","purl":"pkg:npm/poly-custom-api"},"versions":["5.3.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"poly-custom-api-5.3.1.tgz","hashes":{"sha512_sri":"sha512-RSR9waszWVq+MZd+I7SpD7Nl7L6rKVM8CLcLlEFXtKV+xAPt8oAbFca1z/EzyOvr86tGaRVXFTURXE/9vScfeA==","sha1":"09dc2e523079cf687c0330e52558c97354e5abca"}}],"evidence_files":[{"sha256":"ce2c680ca6b7355d73cbc131465fc6b2f2508f367b57ecb27a3b05e6e247213f","tlsh":"30c1616546fa31a36a67e4eef30f10027165e313365de971f48e42902fca568e5f24e8","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/poly-custom-api/MAL-2026-12416.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}