{"id":"MAL-2026-13449","summary":"Malicious code in merchantweb-lang-cookie-reset (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fff16333aa7ffc7fc2c7decc1458c23b7d89f8caacb5c6129ba76168d08ec4be)\npackage.json declares the sole dependency `packet-table-thread-stream` as a direct tarball URL to a non-npm host (`https://artifacts.yosiroute.com/npm/packet-table-thread-stream`), with no version pin and no integrity hash. The shrinkwrap marks that dependency `hasInstallScript: true`, so on `npm install` npm fetches opaque code from `artifacts.yosiroute.com` and executes its lifecycle scripts on the installer's machine, bypassing npm registry scanning. The wrapper package itself is a disposable shim: index.js is trivial (only re-exports name/version), and package.json metadata is placeholder (`author: Package Registry`, `description: Generated package`, `repo: github.com/example/...`). The package's only functional effect on install is pulling attacker-controlled code from a non-registry host into the installer's dependency tree and running its install scripts.\n","modified":"2026-08-07T14:49:44.483497625Z","published":"2026-08-06T16:15:13Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-06T18:09:03.403884105Z","modified_time":"2026-08-06T16:15:13Z","sha256":"5b095c93acc24b5979596513da816a08ab69de453c893e346f8c825985d3ec0b","source":"amazon-inspector","versions":["99.99.99"],"id":"IN-MAL-2026-016667"},{"id":"IN-MAL-2026-017089","import_time":"2026-08-07T14:26:54.925407899Z","modified_time":"2026-08-07T13:46:41Z","sha256":"7e12670f9987338fc995e1eb0bf13cd6bf0949656b1cfdc16a1c87988f391029","source":"amazon-inspector","versions":["1.0.998"]},{"versions":["2.0.0"],"id":"IN-MAL-2026-017091","import_time":"2026-08-07T14:26:55.066408883Z","modified_time":"2026-08-07T13:46:57Z","sha256":"1473abd9b4bdf4c1e4ae3ea2792df1a7b7767afadf997d2eb462be4e4812c9d4","source":"amazon-inspector"},{"id":"IN-MAL-2026-017084","import_time":"2026-08-07T14:26:54.610603265Z","modified_time":"2026-08-07T13:45:57Z","sha256":"6fdc64548a3943481f8f5e68ad242d3b24a4b2a54e43f4e1c4559dc3623b4148","source":"amazon-inspector","versions":["0.1.999"]},{"id":"IN-MAL-2026-017085","import_time":"2026-08-07T14:26:54.703599192Z","modified_time":"2026-08-07T13:46:07Z","sha256":"b5168eae14721870b10af6cfc658a8692171995688bc5510d47d2875cf0b8e9f","source":"amazon-inspector","versions":["0.999.999"]},{"import_time":"2026-08-07T14:26:54.813021245Z","modified_time":"2026-08-07T13:46:24Z","sha256":"c21581066774b18d7569363233c1dbd287cf32939ee1c06c86df5990667cff01","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-017087"},{"source":"amazon-inspector","versions":["1.999.999"],"id":"IN-MAL-2026-017090","import_time":"2026-08-07T14:26:54.968911453Z","modified_time":"2026-08-07T13:46:50Z","sha256":"d58c93de4adbdacdad567bfcb3e7c0c12d59d7b55f05ecac8bebed49f63a204c"},{"import_time":"2026-08-07T14:26:54.866495141Z","modified_time":"2026-08-07T13:46:34Z","sha256":"f8b4bd334cad5c530726d1072d7ef97d0d22c4d73f6def5a63c8a1a9bfea2598","source":"amazon-inspector","versions":["1.0.999"],"id":"IN-MAL-2026-017088"},{"source":"amazon-inspector","versions":["0.0.999"],"id":"IN-MAL-2026-017083","import_time":"2026-08-07T14:26:54.555423536Z","modified_time":"2026-08-07T13:45:44Z","sha256":"fff16333aa7ffc7fc2c7decc1458c23b7d89f8caacb5c6129ba76168d08ec4be"},{"import_time":"2026-08-07T14:26:54.745527734Z","modified_time":"2026-08-07T13:46:16Z","sha256":"4d66244af69164db5f24314f3e0e4f9dd478599763adbf9f6fbd0a6ea55c8cf0","source":"amazon-inspector","versions":["0.0.6"],"id":"IN-MAL-2026-017086"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/99.99.99"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/1.0.998"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/2.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/0.1.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/0.999.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/0.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/1.999.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/1.0.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/0.0.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/merchantweb-lang-cookie-reset/v/0.0.6"}],"affected":[{"package":{"name":"merchantweb-lang-cookie-reset","ecosystem":"npm","purl":"pkg:npm/merchantweb-lang-cookie-reset"},"versions":["99.99.99","1.0.998","2.0.0","0.1.999","0.999.999","0.1.0","1.999.999","1.0.999","0.0.999","0.0.6"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"ec87e43dfa088eb04e0e7390f0133169f71adf5d","sha512_sri":"sha512-wB/2nNHxpKGl8UauABjQIxwQE/+IQs4Wy8epQ5dkazZidVQDthoW5fJSavfeg4iWEQ85LFLBJETUWfQy9aT7RQ=="},"filename":"merchantweb-lang-cookie-reset-99.99.99.tgz"}],"evidence_files":[{"tlsh":"1df04669c16a79f352d2a6e885758943a963c00f510c685dbb9cc019cf0e5ab34b5a08","path":"npm-shrinkwrap.json","sha256":"08861f89f25f8a326cadf906823bb7a2a5c6c1b8cb619704c56dfa69e740d4a9"},{"path":"package.json","sha256":"1f24d7f512fba7b853e6ed55acb38035b7201621295739331daae1ef7f5653e0","tlsh":"ebf02038c618a6b34ad509d89c655843aa278d1fe208b8999bd2c13a870e09728be91d"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/merchantweb-lang-cookie-reset/MAL-2026-13449.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}