{"id":"MAL-2026-12805","summary":"Malicious code in strath (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b9ae02b92920c1e028b5785e69013ea4662e4eb3180872531d64ccca00eef239)\nThe package declares a postinstall script that runs dist/config.js. That script fetches JSON from https://my-api.trade-api.workers.dev?id=2 and then executes `globalThis[data.success](data.id)`, where both the method name and its argument are supplied by the remote server. This gives the operator of that endpoint arbitrary code execution on any machine that runs `npm install strath` — the invocation fires automatically as part of the default install lifecycle. The behavior is unrelated to the package's advertised path-utility purpose. The same script also references `globalThis[tag](text)` with undefined identifiers, consistent with a deliberately opaque dropper shape rather than a normal build step.\n","modified":"2026-08-05T14:37:22.814128908Z","published":"2026-08-05T13:36:26Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:19:49.42263874Z","modified_time":"2026-08-05T13:37:43Z","sha256":"12c207beb2ff9be81457e36a86a366dc7372548d0c34ea05c93c5a3e75d387c8","source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-014985"},{"source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-014984","import_time":"2026-08-05T14:19:49.338430832Z","modified_time":"2026-08-05T13:36:26Z","sha256":"b9ae02b92920c1e028b5785e69013ea4662e4eb3180872531d64ccca00eef239"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/strath/v/1.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/strath/v/1.1.0"}],"affected":[{"package":{"name":"strath","ecosystem":"npm","purl":"pkg:npm/strath"},"versions":["1.1.1","1.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"dist/config.js","sha256":"5519f42578caff8d2436a9c42f496a92f6aa14f576521e6cef2ab717d98c2a45","tlsh":"0ed0977bc28da028782470ddd0090220b083e9228b2e840bea1eead19cd5820ea00134"}],"package_integrity":[{"filename":"strath-1.1.1.tgz","hashes":{"sha512_sri":"sha512-cYX9Q1GkaBvBOqSo2xT7intX3glNwbDELA/dGEn0pkQbmn2m7786K/P5iYqpck2/fWNpa2zObiTeqCcVgcv5kw==","sha1":"af10b49ca798a7f6d1d698494d388c82068e66db"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/strath/MAL-2026-12805.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}