{"id":"MAL-2026-13358","summary":"Malicious code in app-kst-engine (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (08cfc426d2f4b29bba2b81f2eb56eeee32ab114338a51fae5eeced2571e6b2d9)\nOn npm install, package.json's postinstall runs `node test.js`, which triggers three malicious paths against the installer. (1) A recursive scan of the current working directory collects files matching id.json, config.toml, Config.toml, env, and.env, prefixes each with the installer's username, and POSTs them to http://170.205.31.203:3000/api/v1. (2) Scan patterns are fetched from http://170.205.31.203:3001/api/scan-patterns and used to walk the user's home directory on Unix or enumerate every logical drive on Windows (via wmic/PowerShell), uploading matching files with username and platform metadata to http://170.205.31.203:3001/api/v1. (3) On Linux, an attacker-supplied SSH public key is fetched from the same C2 and appended to ~/.ssh/authorized_keys with mode 0o600, then `sudo ufw allow 22/tcp` is invoked to open the firewall, granting persistent remote SSH access. The destination is a hardcoded bare-IP endpoint with no relation to any documented package purpose.\n","modified":"2026-08-05T18:19:49.192231299Z","published":"2026-08-05T17:22:35Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015831","import_time":"2026-08-05T18:07:50.471941577Z","modified_time":"2026-08-05T17:22:35Z","sha256":"08cfc426d2f4b29bba2b81f2eb56eeee32ab114338a51fae5eeced2571e6b2d9","source":"amazon-inspector","versions":["2.1.6"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/app-kst-engine/v/2.1.6"}],"affected":[{"package":{"name":"app-kst-engine","ecosystem":"npm","purl":"pkg:npm/app-kst-engine"},"versions":["2.1.6"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"306b98eaa8833598d7ad27bebfb2e40bb543e692","sha512_sri":"sha512-m63B/uKfUcmCNsvj1RWr5FcZui+XLwtWEydPH5ojn3S0yqKmJnn+xEDK5Pzt1zOjnumilSfsKT0I8Mvk1MLYzg=="},"filename":"app-kst-engine-2.1.6.tgz"}],"evidence_files":[{"sha256":"d986a2e0a9eb3fc3781e166ff6b700e0d38249a6c9649982243c3754671f42d9","tlsh":"ef02934ca6fb2a2183b371ac468f1415b59ac0033949cd81b2cc97546f8f93d65f6ede","path":"index.js"},{"sha256":"8296bee9db2ba7b59b3078e94f24e8a38f4a61d7f631e390180c3c2553709ff9","tlsh":"b9f0ed27ca588e6318f176a868bc0617f681932f4100880f35bd274c4fb61330089f1e","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/app-kst-engine/MAL-2026-13358.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}