{"id":"MAL-2026-13690","summary":"Malicious code in @noobaihome/amis-uni-area-widget (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561)\nscripts/install.js runs during npm preinstall and performs three attacker-beneficial actions against the installer host. First, it unconditionally beacons installer identifiers (pid, base64-encoded process.cwd(), base64-encoded process.env.INIT_CWD, and a marker) over plain HTTP to the hardcoded bare-IP endpoint http://49.232.169.67:43817/bsrc-r260. Second, when a parent build manifest matches an internal marker, it downloads a shell script from http://49.232.169.67:80/slt via curl (with a wget fallback) and pipes the response into /bin/sh through spawnSync, giving the remote host arbitrary code execution on the installer at install time. Third, it fetches http://bsrc-ssrf.n.baidu-int.com/bsrc_uid — an internal-network endpoint reachable only from inside a specific corporate network — and forwards the base64-encoded response body back to the same 49.232.169.67:43817 callback, characteristic of an SSRF-driven internal reconnaissance probe. The destination is a bare IPv4 address on plain HTTP with no relationship to any documented publisher, the fetched shell script is unpinned and unverified, and all three behaviors fire automatically on npm install.\n","modified":"2026-08-10T12:50:24.488131264Z","published":"2026-08-10T11:54:13Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-10T12:24:45.518303263Z","modified_time":"2026-08-10T11:55:16Z","sha256":"15510a6c21ecdd743474138e5ce36700a133705b31ab4e9d1651d298feaf66f8","source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-017240"},{"import_time":"2026-08-10T12:24:45.730864322Z","modified_time":"2026-08-10T11:55:33Z","sha256":"2518f3a152632cdb5e9fe503102eb09f8ba7b79a6b8ea5f9ecc193206a8c2b6b","source":"amazon-inspector","versions":["1.0.8"],"id":"IN-MAL-2026-017242"},{"source":"amazon-inspector","versions":["1.0.11"],"id":"IN-MAL-2026-017238","import_time":"2026-08-10T12:24:45.280902346Z","modified_time":"2026-08-10T11:54:58Z","sha256":"517ad8810b4a12e80381570f0ec88b7b708d810c97a2a90711ae68172c9af51a"},{"sha256":"87b5f72e01a3ae3eabab4af272133f2a3536a47aa2444b8b810a241ac6ef8b09","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-017241","import_time":"2026-08-10T12:24:45.638971752Z","modified_time":"2026-08-10T11:55:26Z"},{"versions":["1.0.4"],"id":"IN-MAL-2026-017243","import_time":"2026-08-10T12:24:45.883181069Z","modified_time":"2026-08-10T11:55:42Z","sha256":"9dc6a9f3ec560cd4e83b7682e81c6349aa184892de353e807c41b3576a59a743","source":"amazon-inspector"},{"modified_time":"2026-08-10T11:55:07Z","sha256":"c5d7fdcc7c80d935460b3c3080915e805c96d6ea904593786afd9d985439a511","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-017239","import_time":"2026-08-10T12:24:45.412722281Z"},{"sha256":"ca5d69656e3a385d08858223b6c6ca2abbef7896020921f5319f874dd39588e4","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-017233","import_time":"2026-08-10T12:24:44.812053977Z","modified_time":"2026-08-10T11:54:13Z"},{"source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-017236","import_time":"2026-08-10T12:24:45.087805026Z","modified_time":"2026-08-10T11:54:41Z","sha256":"1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561"},{"versions":["1.0.5"],"id":"IN-MAL-2026-017237","import_time":"2026-08-10T12:24:45.182843879Z","modified_time":"2026-08-10T11:54:51Z","sha256":"9e842cae97f83fd281bc9949bf01908a87bd08d885cef712d2dd7c021601939e","source":"amazon-inspector"},{"modified_time":"2026-08-10T11:54:29Z","sha256":"d055000a3d6bd5333d0c4edc67a78f31703a56f2766fec9227a7c611ddae3a55","source":"amazon-inspector","versions":["1.0.10"],"id":"IN-MAL-2026-017235","import_time":"2026-08-10T12:24:45.003788111Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.11"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.10"}],"affected":[{"package":{"name":"@noobaihome/amis-uni-area-widget","ecosystem":"npm","purl":"pkg:npm/%40noobaihome/amis-uni-area-widget"},"versions":["1.0.7","1.0.8","1.0.11","1.0.1","1.0.4","1.0.6","1.0.0","1.0.2","1.0.5","1.0.10"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@noobaihome/amis-uni-area-widget/MAL-2026-13690.json","indicators":{"evidence_files":[{"tlsh":"6171976729f728669b53d0d8a21b4826b61281433997c9f4b94c03942fc7074d573afd","path":"dist/bsrc-loader.js","sha256":"7c2ddfe2a4d569f1059d7d5de6a8e7f220a5fdf8b37b14a1b0b688557ccd8dcd"}],"package_integrity":[{"filename":"amis-uni-area-widget-1.0.7.tgz","hashes":{"sha512_sri":"sha512-TDaYSBk06aimZebC/5I5kdQ6QrisSYxtfL9wstNy19pl++cO9sdEbVIw330AuoLlZyaIo3wKGF6cCYoqSQFSgw==","sha1":"35ced38edc44097413f104270a7ecafaa039c952"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}