{"id":"MAL-2026-12798","summary":"Malicious code in npm-groat (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (eda7da760041a49d296b9a6e8cfa90ec4b7e5daecebbf50c88d41f7fd559a1b1)\nnpm-groat@1.1.1 declares a postinstall script that executes dist/config.js on npm install. That script performs an outbound fetch to https://my-api.trade-api.workers.dev?id=0 and then evaluates the response by calling globalThis[data.success](data.id) — treating attacker-controlled JSON fields as the name of a global function (e.g. eval or Function) and its argument. This gives the remote endpoint arbitrary code execution on the installer's host during package installation. The same file also contains a bare globalThis[tag](text) referencing undeclared identifiers, consistent with a dead-drop stager rather than legitimate configuration. The package's advertised purpose has no need to contact a remote server at install time.\n","modified":"2026-08-05T14:37:17.147092258Z","published":"2026-08-05T13:17:59Z","database_specific":{"malicious-packages-origins":[{"versions":["1.1.2"],"id":"IN-MAL-2026-014963","import_time":"2026-08-05T14:19:47.267646994Z","modified_time":"2026-08-05T13:17:59Z","sha256":"2188ca632e649f444536268f4d76e0d258b0a0b39436573b7ac4f07df440ffa3","source":"amazon-inspector"},{"import_time":"2026-08-05T14:19:47.356126379Z","modified_time":"2026-08-05T13:18:09Z","sha256":"eda7da760041a49d296b9a6e8cfa90ec4b7e5daecebbf50c88d41f7fd559a1b1","source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-014964"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/npm-groat/v/1.1.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/npm-groat/v/1.1.1"}],"affected":[{"package":{"name":"npm-groat","ecosystem":"npm","purl":"pkg:npm/npm-groat"},"versions":["1.1.2","1.1.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"npm-groat-1.1.2.tgz","hashes":{"sha1":"337e650526460050ba32b2f77e5f0d8b7f37246b","sha512_sri":"sha512-kmil046Xri8zqkkAcROLhI28EdPSJ04sH34oHH9UFU5uchDxV9V6kcmud+A1M0yQ2dobuq5/9LQPM3yzMVqVsA=="}}],"evidence_files":[{"tlsh":"43d0977bc28da028681070ddd0090230b083e5228b2e840bea1dead19cd5a20ea00130","path":"dist/config.js","sha256":"ef91514dc36b5af51d5e1564233e565861e659e309f0848d8cefedf163d04621"},{"path":"package.json","sha256":"40865fd9402acde866e069ffb4685df6dcb612f47c9690364d1d93b24a44d75a","tlsh":"3501263bc9948e3315f4dba26d260742fa210b1f11a44c0bb0be501c0fb219704bbbb9"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npm-groat/MAL-2026-12798.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}