{"id":"MAL-2026-13423","summary":"Malicious code in fetchrtds (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (74e0a6afc9e0684beee9d75d2f4966507178bed2499c8f5453629a0b827a80ef)\nOn npm install, the package's postinstall script reads a config URL (defaulting to https://slimopump.vercel.app/config/clob-math.json), fetches a.tgz bundle referenced by that config, extracts it, runs `npm install` inside the extracted directory, then require()s the extracted `peer-math.js` and invokes `syncSession()`. The remote bundle is unpinned and unverified (no hash/signature check), and the host is not the package's registry or a publisher-matched domain, so arbitrary Node code chosen by the operator of slimopump.vercel.app executes on the installer's machine at install time. The advertised purpose (Polymarket/Chainlink TWAP via RTDS WebSocket) does not match the shipped code, which is limited to a trivial Kelly-stake arithmetic helper (computeKellyStake/formatStakeUsd/roundStake) — the functional payload is delivered exclusively via the postinstall fetch.\n","modified":"2026-08-06T14:34:49.773096095Z","published":"2026-08-06T13:56:39Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016547","import_time":"2026-08-06T14:19:54.861291768Z","modified_time":"2026-08-06T13:56:39Z","sha256":"74e0a6afc9e0684beee9d75d2f4966507178bed2499c8f5453629a0b827a80ef","source":"amazon-inspector","versions":["1.1.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fetchrtds/v/1.1.0"}],"affected":[{"package":{"name":"fetchrtds","ecosystem":"npm","purl":"pkg:npm/fetchrtds"},"versions":["1.1.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"fetchrtds-1.1.0.tgz","hashes":{"sha1":"2befab02b56bbb8e2440ef6b1755ad646705301f","sha512_sri":"sha512-d1BNLgAp9oQtmuqPa5nHuOx8gTUZlx5j+1VMFIGl+WHvt5JqFrx9PNrW2eyJOHXNs9LQ3kZib0PcNYejicWAhg=="}}],"evidence_files":[{"sha256":"3e15f1692c4075cf29cefa94c84d564a95086ab7a6838a97ea25cd02475a282d","tlsh":"6ad1659915a272770bb0e7a4cb53a41eeb6394233511c364f6cdc6952ff6164c213dec","path":"scripts/install-check.cjs"},{"sha256":"20bd28b0dfedcff6a8b1eaa77ecaa7928140269ddaaa3019b5c5ce7750d2dd43","tlsh":"c7f02837daa08d3728b8ca8a59255000f5554b2f62a44c0bb1bba15c8fb756205abb65","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fetchrtds/MAL-2026-13423.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}