{"id":"MAL-2026-13733","summary":"Malicious code in newtun (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (adc90e76cf26bdb3145704cfb477f3a5215670556d03ff2959dde595a8bb0598)\nThe newtun CLI opens a plaintext WebSocket to the hardcoded server pull.7ii.win:7999 and hands the remote peer complete control of the installer's host. On TERM_OPEN messages the client calls pty.spawn(shell,...) and pipes server-supplied bytes (base64-decoded) directly into term.write(), giving the remote server an interactive PTY shell as the process user. SCRIPT_LIST/POLICY_SCRIPTS messages pass server-controlled string content to child_process.exec() and return stdout/stderr/exit code back over the same socket. FILE_REQUEST messages dispatch fs.readdirSync / readFileSync / writeFileSync / unlinkSync / rmSync / renameSync / mkdirSync against server-supplied paths, with file contents shipped back base64-encoded (up to 10MB per read) — allowing the operator to exfiltrate ~/.ssh, ~/.aws, and other installer secrets and to plant or delete files anywhere the process user can write. Every 5 seconds the client also sends MONITOR frames carrying hostname, OS type/release, arch, Node version, CPU/memory/load, uptime, and /proc/net/dev RX/TX rates; the initial authenticate frame carries os.hostname(), os.type/release/arch, and process.version. An UPGRADE control message causes the client to run `npm update -g newtun` and relaunch, letting the remote server swap the globally installed binary for any future published version without user interaction. The transport is unauthenticated plain ws:// so any on-path party can also drive these primitives.\n","modified":"2026-08-11T12:30:11.122605394Z","published":"2026-08-11T12:19:28Z","database_specific":{"malicious-packages-origins":[{"sha256":"10824263dc9e32215d3e220d20b6de089f684d53f71b2574f181c98daae0abf4","source":"amazon-inspector","versions":["1.0.20"],"id":"IN-MAL-2026-017346","import_time":"2026-08-11T12:23:10.271014562Z","modified_time":"2026-08-11T12:21:54Z"},{"import_time":"2026-08-11T12:23:09.430120308Z","modified_time":"2026-08-11T12:20:24Z","sha256":"adc90e76cf26bdb3145704cfb477f3a5215670556d03ff2959dde595a8bb0598","source":"amazon-inspector","versions":["1.0.14"],"id":"IN-MAL-2026-017336"},{"versions":["1.0.18"],"id":"IN-MAL-2026-017339","import_time":"2026-08-11T12:23:09.716272053Z","modified_time":"2026-08-11T12:20:52Z","sha256":"b607f8c68e609c5cdd110266221d162b74f804210d537866f32a416ffc53d956","source":"amazon-inspector"},{"versions":["1.0.25"],"id":"IN-MAL-2026-017330","import_time":"2026-08-11T12:23:08.925047195Z","modified_time":"2026-08-11T12:19:28Z","sha256":"250220a094a1f5602311f6e852e02110a606e099bc58981bbfe423daf07f60cf","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["1.0.12"],"id":"IN-MAL-2026-017337","import_time":"2026-08-11T12:23:09.50086685Z","modified_time":"2026-08-11T12:20:33Z","sha256":"54a3c9472294a912f954c8660d904752aab0c5c07ba662bf65e66e99f01ba7d7"},{"versions":["1.0.26"],"id":"IN-MAL-2026-017334","import_time":"2026-08-11T12:23:09.232257143Z","modified_time":"2026-08-11T12:20:05Z","sha256":"bfc53f84f3fdc42574b025a376f29630faf5d5a6db55e9bc1191624ef4255f86","source":"amazon-inspector"},{"modified_time":"2026-08-11T12:21:18Z","sha256":"bfe1f5dbf1f2889230487c5d57840d826ec0783ecada63469b1134cbec7d7abb","source":"amazon-inspector","versions":["1.0.21"],"id":"IN-MAL-2026-017342","import_time":"2026-08-11T12:23:09.936368648Z"},{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-017351","import_time":"2026-08-11T12:23:10.687063961Z","modified_time":"2026-08-11T12:22:34Z","sha256":"d9178e3713e40cdd7a4b31dcdc6e82e2febedad348145dc7e20531a96b57e680"},{"source":"amazon-inspector","versions":["1.0.13"],"id":"IN-MAL-2026-017338","import_time":"2026-08-11T12:23:09.622124387Z","modified_time":"2026-08-11T12:20:44Z","sha256":"feed96ac1b104b441cbb5bffe48e7f830882bcb379155eaea8605bc6272b9e13"},{"sha256":"6fc10f37d7ac7e45368f970a5a479612a70bf9fafea0896aa0406ef9e76ee57c","source":"amazon-inspector","versions":["1.0.8"],"id":"IN-MAL-2026-017345","import_time":"2026-08-11T12:23:10.196186524Z","modified_time":"2026-08-11T12:21:45Z"},{"import_time":"2026-08-11T12:23:10.120346571Z","modified_time":"2026-08-11T12:21:34Z","sha256":"9a1248a5a71f269da11a6c21266b850a510fd28bd967226e6e8c1ec98a17f07f","source":"amazon-inspector","versions":["1.0.27"],"id":"IN-MAL-2026-017344"},{"modified_time":"2026-08-11T12:19:46Z","sha256":"afc61cd45471791e81e7219dc417c5553357589bba81b24774514d1e0e06a3fd","source":"amazon-inspector","versions":["1.0.16"],"id":"IN-MAL-2026-017332","import_time":"2026-08-11T12:23:09.072617284Z"},{"id":"IN-MAL-2026-017343","import_time":"2026-08-11T12:23:10.045493474Z","modified_time":"2026-08-11T12:21:27Z","sha256":"13b0697d9e7fd93da6a8a5fc611ea13d6ad3885b05e9707eee12dd8d5cb52553","source":"amazon-inspector","versions":["1.0.24"]},{"import_time":"2026-08-11T12:23:09.308195115Z","modified_time":"2026-08-11T12:20:14Z","sha256":"29ffdd16abfc0bfa179e4ee663c6dc3ade18914fc8eda8389eb5da44cbd8a1c6","source":"amazon-inspector","versions":["1.0.11"],"id":"IN-MAL-2026-017335"},{"import_time":"2026-08-11T12:23:09.789093598Z","modified_time":"2026-08-11T12:21:01Z","sha256":"2a533a6a01df200b7fe2aa9e16275f9e8e08f8e631dd621a22ecda41bf4d29f2","source":"amazon-inspector","versions":["1.0.17"],"id":"IN-MAL-2026-017340"},{"sha256":"6864bfd4c408771ad2f8a8cb718f3bb29edcc2986fb3fcf09cb77b36ab06453d","source":"amazon-inspector","versions":["1.0.23"],"id":"IN-MAL-2026-017348","import_time":"2026-08-11T12:23:10.457602384Z","modified_time":"2026-08-11T12:22:10Z"},{"sha256":"8be97e3384f529f6b3cc412e1e207bb36022d23604b83a09b0768f0e66c5ba14","source":"amazon-inspector","versions":["1.0.19"],"id":"IN-MAL-2026-017333","import_time":"2026-08-11T12:23:09.147577433Z","modified_time":"2026-08-11T12:19:53Z"},{"id":"IN-MAL-2026-017350","import_time":"2026-08-11T12:23:10.611741814Z","modified_time":"2026-08-11T12:22:27Z","sha256":"987e887581aae8d08d592490642a4089c72bd19b15b7f18089088758c441f42d","source":"amazon-inspector","versions":["1.0.2"]},{"sha256":"a02551d7887d5d855587c96e21458f02aa15268d0bbf6d07df966408acb70362","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-017349","import_time":"2026-08-11T12:23:10.533003326Z","modified_time":"2026-08-11T12:22:17Z"},{"versions":["1.0.3"],"id":"IN-MAL-2026-017347","import_time":"2026-08-11T12:23:10.347355041Z","modified_time":"2026-08-11T12:22:02Z","sha256":"a0caa8712aa6037e1bfa9cf5ec3a9da52fecebdd4afcc5b26e18740fb562c2c7","source":"amazon-inspector"},{"import_time":"2026-08-11T12:23:08.99670604Z","modified_time":"2026-08-11T12:19:38Z","sha256":"a0deb6bf2b7444c801814b65d3758e84e25f0a9d72038d5ddc0b95289a61a83c","source":"amazon-inspector","versions":["1.0.15"],"id":"IN-MAL-2026-017331"},{"import_time":"2026-08-11T12:23:09.861684346Z","modified_time":"2026-08-11T12:21:11Z","sha256":"aa9de12f8c7eedf554ee25df6fc0a9377470180b18396c3258371bc5fc27db74","source":"amazon-inspector","versions":["1.0.22"],"id":"IN-MAL-2026-017341"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.20"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.14"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.18"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.25"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.12"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.26"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.21"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.13"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.27"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.16"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.24"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.11"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.17"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.23"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.19"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.15"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/newtun/v/1.0.22"}],"affected":[{"package":{"name":"newtun","ecosystem":"npm","purl":"pkg:npm/newtun"},"versions":["1.0.20","1.0.14","1.0.18","1.0.25","1.0.12","1.0.26","1.0.21","1.0.1","1.0.13","1.0.8","1.0.27","1.0.16","1.0.24","1.0.11","1.0.17","1.0.23","1.0.19","1.0.2","1.0.0","1.0.3","1.0.15","1.0.22"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"c8bc1258b4424ff274357c80eb900d352f057ed7eab77be80694ca1684fbf2d3","tlsh":"a2c2feda6aff4061d17379685f0f64212315e00b390bed5cbe5ce3909f625b894a2fe8","path":"dist/client.js"},{"path":"dist/index.js","sha256":"6a38b179399510ce1fe6da9679bf3f637f81aa3084ef4b50df182624f2e27b76","tlsh":"f01232885cfb04b56927ae351b3f9812372969036109f8183b9cd3d59ff186ccd936ae"}],"package_integrity":[{"hashes":{"sha1":"d7113796b916982c9ac82d533b40992a121f0ebe","sha512_sri":"sha512-/gtWraq5CL/ADkctbWXtM9u7ebZBeGNVDioa0lc4V3invEA9Gd7EsCJ//DFAi6QJLMlfTI/OtxzlUHbTaP88hA=="},"filename":"newtun-1.0.20.tgz"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/newtun/MAL-2026-13733.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}