{"id":"MAL-2026-13689","summary":"Malicious code in @noobaihome/amis-simple-area-widget (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (642f206459c4677892954c26736b990c72bb01ae9383f917ab664b38d977819f)\n@noobaihome/amis-simple-area-widget@1.0.0 advertises an AI Suda amis area-chart widget, but dist/renderer.umd.js and dist/plugin.umd.js are empty stubs (module.exports = {}). The only functional code is scripts/install.js, invoked from a preinstall lifecycle hook, which on npm install fetches http://bsrc-ssrf.n.baidu-int.com/bsrc_uid (an internal-only Baidu host reachable only from an installer inside that network perimeter) and POSTs the base64url-encoded response, along with a marker string 'BSRC_RCE_R255_7e49c2', to a hardcoded external IP callback at http://49.232.169.67:43817/bsrc-r255. The package name is a dependency-confusion lure against an internal @noobaihome scope. Installing the package causes outbound traffic from the installer's environment to an attacker-chosen public IP carrying content only reachable from inside the target's private network — a blind SSRF / dependency-confusion probe, regardless of any stated bug-bounty framing.\n","modified":"2026-08-10T12:50:36.964938257Z","published":"2026-08-10T11:55:51Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017244","import_time":"2026-08-10T12:24:45.984040839Z","modified_time":"2026-08-10T11:55:51Z","sha256":"642f206459c4677892954c26736b990c72bb01ae9383f917ab664b38d977819f","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-simple-area-widget/v/1.0.0"}],"affected":[{"package":{"name":"@noobaihome/amis-simple-area-widget","ecosystem":"npm","purl":"pkg:npm/%40noobaihome/amis-simple-area-widget"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"scripts/install.js","sha256":"86763e2e5283a5664d9a03dbadffc356fbbc86a90c78414dd1c53aaca1140da2","tlsh":"fd310f6a38f725660773f4cc462b8d68f222810320edcfa0ba5d07610f82534d6b12aa"}],"package_integrity":[{"hashes":{"sha1":"e8eaaf0049763ecca4e167aad276c9540d113c56","sha512_sri":"sha512-CIOFXNfJn690WAUtOMtrisOiCW/XVd+tSvncgPfxsC9miDcqksSdpY6PEN/oNVGFUWqlnVgpnQYGu2DEoQ4A6w=="},"filename":"amis-simple-area-widget-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@noobaihome/amis-simple-area-widget/MAL-2026-13689.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}