{"id":"MAL-2026-12496","summary":"Malicious code in voicemail (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (568a31285f414d8125b5749bc8e070157ffd403ce46e46da637cc1452f99d19f)\npackage.json declares both preinstall and postinstall lifecycle scripts that invoke curl against a hardcoded webhook.site endpoint (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots) with query parameters carrying the installer's username ($(whoami)), hostname ($(hostname)), current working directory ($PWD), and a timestamp. The beacon fires automatically on `npm install` without user consent, sending host and identity reconnaissance to an attacker-controlled collector. The package provides no legitimate functionality corresponding to this network activity.\n","modified":"2026-08-05T14:37:28.569710464Z","published":"2026-08-05T13:08:12Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T13:08:53.587371291Z","modified_time":"2026-08-05T13:08:12Z","sha256":"6d31c2930aaf259b45a56e869bc0ee9293486c708895bf10d7438a580fe31aea","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014896"},{"modified_time":"2026-08-05T13:08:28Z","sha256":"568a31285f414d8125b5749bc8e070157ffd403ce46e46da637cc1452f99d19f","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-014898","import_time":"2026-08-05T14:19:40.991053972Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/voicemail/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/voicemail/v/1.0.2"}],"affected":[{"package":{"name":"voicemail","ecosystem":"npm","purl":"pkg:npm/voicemail"},"versions":["1.0.1","1.0.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/voicemail/MAL-2026-12496.json","indicators":{"evidence_files":[{"sha256":"97a010484c94a739dcef66e9028c45218badccf188df4cfc88e3bb8287f90360","tlsh":"c5f081b6483a74733ec641543e4d820a7904bb2b9511b5076723e92814cde6b557a367","path":"package.json"}],"package_integrity":[{"filename":"voicemail-1.0.1.tgz","hashes":{"sha512_sri":"sha512-OTRHIVy+PogMcO9mqwTnCGbqYcmpjX5uchkoePWUPwgyBlSla0GxZYBz9atD+DFLangni+eYAvdHI0FVPRgzJQ==","sha1":"47c5c679ae23fd601eac384974aaa460b5b7c773"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}