{"id":"MAL-2026-13940","summary":"Malicious code in @opezneppelin/contracts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (abe04ec28ed56cb0a253131129df8078d425f8a0c579c439ced9c75b6977a6ab)\n@opezneppelin/contracts is a typosquat of @openzeppelin/contracts. Its postinstall lifecycle script (scripts/postinstall.js) hex-escapes all module names, method names, and string constants (fs, https, child_process, powershell, -NoP,.exe) and stores the download URL as a base64 literal that decodes to https://files.catbox.moe/9bppy2.zip. On Windows installers, the script downloads that ZIP to %TEMP%, expands it via PowerShell Expand-Archive, recursively searches the extracted contents for the first.exe, and spawns it detached. The destination is an anonymous, mutable file-host (catbox.moe) unrelated to any OpenZeppelin infrastructure, and the fetched executable is opaque attacker-controlled content. The behavior fires automatically on npm install without any user action, resulting in arbitrary code execution on the installer's Windows host.\n","modified":"2026-08-13T17:30:11.184856810Z","published":"2026-08-13T17:17:31Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-13T17:24:45.875181164Z","modified_time":"2026-08-13T17:17:31Z","sha256":"abe04ec28ed56cb0a253131129df8078d425f8a0c579c439ced9c75b6977a6ab","source":"amazon-inspector","versions":["5.0.2"],"id":"IN-MAL-2026-017647"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@opezneppelin/contracts/v/5.0.2"}],"affected":[{"package":{"name":"@opezneppelin/contracts","ecosystem":"npm","purl":"pkg:npm/%40opezneppelin/contracts"},"versions":["5.0.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"scripts/postinstall.js","sha256":"be0e358b5b4533c985c53d576f99a13ea680a03cda0d0885c50d062e540a043c","tlsh":"cc41eed571d9632b23ec44e7f6245ee581a7dd12b1c9b043831c7a4e14d908acae6dc9"}],"package_integrity":[{"hashes":{"sha1":"4b518ff7f9bf8c5e8fbbadf5413b9d2891411145","sha512_sri":"sha512-Dj5/ri6BPZ2ZHeI2npsZalMnmZOzdytcK0/XEDf+C4Ci0lIK+PXQIEY/gy+8eaj2SNQZYdXFAjDTgIt8HPW+wg=="},"filename":"contracts-5.0.2.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@opezneppelin/contracts/MAL-2026-13940.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}