{"id":"MAL-2026-13921","summary":"Malicious code in envpack-conf (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a061ac72b9e392fee182ad4873aab0cc9a64694a11228438a7838343b96d338f)\nenvpack-conf 1.0.1 is a trojanized copy of the pkg-conf utility. index.js appends a top-level async IIFE that runs whenever the module is imported. The IIFE queries public Ethereum RPC endpoints (eth.blockscout.com/api, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) for transactions sent from the attacker address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes the `to` field of those transactions into two IPv4 addresses, fetches an XOR-encrypted second-stage payload from those hosts at path /0x/cls, and executes the decrypted payload with both eval() and spawn('node',['-e',\u003cpayload\u003e],{detached:true,stdio:'ignore'}).unref(), giving a detached child process on the installer's host. Every sensitive identifier (module names http/https/zlib/child_process, hostnames, HTTP methods, header names, the attacker address, the RPC URLs, request paths, and global variable names) is written as \\uXXXX-escaped literals to evade static analysis. The package name and README (`devpack-conf`) impersonate Sindre Sorhus's `pkg-conf`; package.json lists the author as 'Sinde Sorus' \u003csindesorus@gmail.com\u003e, a typosquat of the real maintainer. The legitimate pkg-conf source is preserved above the injected block as cover.\n","modified":"2026-08-12T16:03:34.319067714Z","published":"2026-08-12T15:36:36Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-017609","import_time":"2026-08-12T15:53:00.513942976Z","modified_time":"2026-08-12T15:36:36Z","sha256":"a061ac72b9e392fee182ad4873aab0cc9a64694a11228438a7838343b96d338f","source":"amazon-inspector"},{"sha256":"df4b13486d2134e1bec02ca3519e60d721da2d320c37ad7c8ffe96f29799eb20","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-017617","import_time":"2026-08-12T15:53:01.332455118Z","modified_time":"2026-08-12T15:41:35Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/envpack-conf/v/1.0.1"}],"affected":[{"package":{"name":"envpack-conf","ecosystem":"npm","purl":"pkg:npm/envpack-conf"},"versions":["1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/envpack-conf/MAL-2026-13921.json","indicators":{"evidence_files":[{"path":"index.js","sha256":"385d89ba18fe9b335c0cd4cb220d5f53ff5a581144e25329f12f3784a388e7a3","tlsh":"972262a45369aeba82325a44cc347d0dd1b8dcb56d4fd06ae82f3c85ec761d08b92a5c"},{"path":"package.json","sha256":"7cf695d6898657df3fa0e2d50d80a08dde30283418b5d4fdbde2ef39ae3c9e9c","tlsh":"dc01f113c62dded303d8aaecac6ed4c7506f904628c698de4cd2f634c2ec250228b056"}],"package_integrity":[{"filename":"envpack-conf-1.0.1.tgz","hashes":{"sha512_sri":"sha512-ySTPHkz7Y+cAPUwFCYbOAMqz4mESV9LwCRaCRdhwTB0uhfsZ45vmzNWmrqfJ3N6pmYk3Vtp5SmDuc6X0N03i9g==","sha1":"32c1ecfb676eb9c24eabea160f05e07e44b20e8f"}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}