{"id":"MAL-2026-12429","summary":"Malicious code in rollup-plugins-check (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5f2c7fe6586c3734730d6f8cd5ffe893c3f7cc5ff82710d1f4df22b8e76987e8)\nThe npm package rollup-plugins-check@0.0.2 declares a postinstall script (`node dist/module.js`) that, on `npm install`, performs an HTTPS GET to https://workconfig.vercel.app with `rejectUnauthorized: false` and passes the response body to `new Function('require', data)(require)`, executing the fetched code inside the installer's Node.js process with access to `require`. The remote body is opaque and controlled by whoever owns the endpoint; TLS certificate verification is explicitly disabled, so any on-path attacker can also substitute the payload. The package advertises itself as a rollup polyfill plugin and ships polyfill code copied from rollup-plugin-polyfill-node as cover, while the dropper is appended to the postinstall entry file. The name resembles the legitimate rollup-plugin-polyfill-node package.\n","modified":"2026-08-05T13:35:52.284760872Z","published":"2026-08-05T13:03:49Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014869","import_time":"2026-08-05T13:08:52.077601125Z","modified_time":"2026-08-05T13:04:05Z","sha256":"2df0babe61716192dc900fc371f95e6b68d67568d680aa54b322a59688fbebeb","source":"amazon-inspector","versions":["0.0.1"]},{"modified_time":"2026-08-05T13:03:49Z","sha256":"5f2c7fe6586c3734730d6f8cd5ffe893c3f7cc5ff82710d1f4df22b8e76987e8","source":"amazon-inspector","versions":["0.0.2"],"id":"IN-MAL-2026-014867","import_time":"2026-08-05T13:08:51.974792452Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/rollup-plugins-check/v/0.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/rollup-plugins-check/v/0.0.2"}],"affected":[{"package":{"name":"rollup-plugins-check","ecosystem":"npm","purl":"pkg:npm/rollup-plugins-check"},"versions":["0.0.1","0.0.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"rollup-plugins-check-0.0.1.tgz","hashes":{"sha1":"3f69accd5b1fefce957ae3445a30caf2a23a9127","sha512_sri":"sha512-iWwIS5HJv4AAIJ1eCHyS1eNM0lzFFPq7TR7dW73Chk3gWVvShr6wcJNWyLO4DqMsguY6YlVEAcTVOWe9/+i/fw=="}}],"evidence_files":[{"path":"dist/module.js","sha256":"b4d6eeb1433696e73d839509c8b8ad9d747fb48fc68200d98c09400e332dd251","tlsh":"0451f67507788bd437a094ea8f51b45ede934ec31212f2e2bc65c158ef38c18b4d9ab8"},{"tlsh":"8b318f30cd5d4ea31ad825fd9876a19390348ad309c5f84833a6421c4f4f67f10bea6e","path":"package.json","sha256":"ef489709ea8b27a3470429bb3981fb06cca900a5210efa0aca2bfb3a95011814"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rollup-plugins-check/MAL-2026-12429.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}