{"id":"MAL-2026-12815","summary":"Malicious code in widget-forge (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5dc77fe941595018023e8382eac28ffdf8d1b000217a0e4d01e56e7bb48ac2d8)\nwidget-forge@9999.0.0 is a dependency-confusion beacon. package.json declares scripts.preinstall = 'node callback.js', which auto-runs on npm install. callback.js collects os.hostname(), os.userInfo().username, process.cwd(), npm_config_registry, and CI repository identifiers (GITHUB_REPOSITORY and related CI env vars) and sends them via HTTP GET to the hardcoded bare-IP endpoint http://75.119.137.232:31337/depconfuse?pkg=.... The package has no functional payload: main is an empty object export, the description is a generic placeholder, and the version 9999.0.0 is the pattern used to outbid internal package versions in dependency-confusion attacks. The only effect of installation is the recon callback to the hardcoded IP.\n","modified":"2026-08-05T14:37:28.566898773Z","published":"2026-08-05T13:18:35Z","database_specific":{"malicious-packages-origins":[{"sha256":"5dc77fe941595018023e8382eac28ffdf8d1b000217a0e4d01e56e7bb48ac2d8","source":"amazon-inspector","versions":["9999.0.0"],"id":"IN-MAL-2026-014967","import_time":"2026-08-05T14:19:47.730209449Z","modified_time":"2026-08-05T13:18:35Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/widget-forge/v/9999.0.0"}],"affected":[{"package":{"name":"widget-forge","ecosystem":"npm","purl":"pkg:npm/widget-forge"},"versions":["9999.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"b341d8f1645821a7fd974fca0867a62745a1d19a93b462ad95b4ade05ddc6809","tlsh":"dd119eb9c68c0c3409c2178079686c1eb8fbd29233c294917f2d71d26bb22b046b71fd","path":"callback.js"},{"tlsh":"bed0a7709e2258232cd8efd30c2b594611668e6b05087c092bc7911d56a96a719ff2ad","path":"package.json","sha256":"377f7309fda6abcd457262235ad94c67a7b7d8607582fca51a11ea1dc13acdc3"}],"package_integrity":[{"filename":"widget-forge-9999.0.0.tgz","hashes":{"sha512_sri":"sha512-l56P18eiY1ufRiPCI6LKVmc8t96hPqMc7A6fZDY81upRDwDQp0haBHMeIlq4OHR3A/chTRiUvoWt/20njfP8QA==","sha1":"c664f0ec4c289ab1cc58232251f5ce90d9f72cc8"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/widget-forge/MAL-2026-12815.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}