{"id":"MAL-2026-14471","summary":"Malicious code in cat-embed-i18n-res (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c612800e80bb36720e75741be9665ab6acbed58bcd5d51065fcedd1d990aaad0)\nThe package's only shipped content, strings.json, is presented as an i18n/translation resource bundle but its values are HTML/JavaScript XSS payloads rather than localized text. Multiple entries use `\u003cimg src=x onerror=...\u003e` and `\u003csvg onload=...\u003e` handlers that invoke fetch() against the hardcoded endpoint https://notpismo.cloud/c, sending `document.domain` and `document.cookie` as query parameters. Any consumer application that renders these strings as HTML (the ordinary use of an i18n bundle in web UIs) will execute the injected script in the end-user's browser and transmit that user's session cookies and hosting domain to notpismo.cloud. The package name and framing as a translation resource are a cover for the payload; there is no legitimate localization content in the file.\n","modified":"2026-08-25T23:49:42.142181590Z","published":"2026-08-25T06:35:38Z","database_specific":{"malicious-packages-origins":[{"sha256":"c612800e80bb36720e75741be9665ab6acbed58bcd5d51065fcedd1d990aaad0","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-018685","import_time":"2026-08-25T06:50:12.477800077Z","modified_time":"2026-08-25T06:35:38Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cat-embed-i18n-res/v/1.0.0"}],"affected":[{"package":{"name":"cat-embed-i18n-res","ecosystem":"npm","purl":"pkg:npm/cat-embed-i18n-res"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"91812910e4c4ba2bfe5c89aa50624eba6123341d102fd528371f430693bbf9a9","tlsh":"28d02ebe72accaab408040e0b011bbf0ec10f81e6829b9e1ca0ebc419a00c22a805523","path":"strings.json"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-vLd12PDJIFw/5OQdv+c5Zssj7ysWyRkqqXkl5LVcb3KGW0Dmwh0hT7a7Kt63+tyzjCxOn7oSQxhNq29ImH7gqA==","sha1":"3de4b41d39156c508e01177a3a4620e69ab19d4a"},"filename":"cat-embed-i18n-res-1.0.0.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cat-embed-i18n-res/MAL-2026-14471.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}