{"id":"MAL-2026-15501","summary":"Malicious code in grafeno-api (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6324266ac0f7a76fc3a8e8209d194daa17bdd47c913207f218f7c1683db4333c)\npackage.json declares a preinstall script that shells out via child_process to curl http://216.126.236.46/x.sh and pipe the response into /bin/bash, running attacker-controlled code on the installer's machine at npm install time. The fetch is unpinned, uses plain HTTP to a bare IP with no integrity check, and is wrapped in a try/catch that suppresses errors. The shipped index.js is a one-line stub exporting a no-op request() function, so the package provides no legitimate functionality — the manifest lifecycle hook is the entire payload, and the 'API client' framing is a cover story.\n\n## Source: ossf-package-analysis (e30333357bace03d536c107ea6180be7a1951073192c1647bcb028e9fac3d633)\nThe OpenSSF Package Analysis project identified 'grafeno-api' @ 1.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-29T02:30:13.006202220Z","published":"2026-08-28T23:02:01Z","database_specific":{"malicious-packages-origins":[{"sha256":"6324266ac0f7a76fc3a8e8209d194daa17bdd47c913207f218f7c1683db4333c","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019063","import_time":"2026-08-28T23:14:35.458633866Z","modified_time":"2026-08-28T23:02:01Z"},{"modified_time":"2026-08-28T23:12:48Z","sha256":"e30333357bace03d536c107ea6180be7a1951073192c1647bcb028e9fac3d633","source":"ossf-package-analysis","versions":["1.0.1"],"import_time":"2026-08-28T23:14:30.532033512Z"},{"modified_time":"2026-08-29T01:42:58Z","sha256":"74b99fb3b240a852af422addece31b9c99411be9e4228edcd3f1ea63fd2ce848","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-019116","import_time":"2026-08-29T02:22:18.377300467Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/grafeno-api/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/grafeno-api/v/1.0.1"}],"affected":[{"package":{"name":"grafeno-api","ecosystem":"npm","purl":"pkg:npm/grafeno-api"},"versions":["1.0.0","1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"grafeno-api-1.0.0.tgz","hashes":{"sha1":"b61d8065bccda490ed342667fa5784935e900bba","sha512_sri":"sha512-R4L0CSb/J+xObpb5Jzr1V5N1zZu0G3vjVjVbrgX1KFj5BRU1u2QN6wm0GmutEajxSGcUDfB0CnxOndQw/k7v7g=="}}],"evidence_files":[{"sha256":"1dbb4d390dfc743b3590aed13067f5da7af49b790cbdb46bc6e472719ae19ae0","tlsh":"43e0d8748920f5b35ac942700e55426276a689060908bd087b47016ca2de3535db955a","path":"package.json"},{"sha256":"aaa058c8dc0de8f775b72666eee548397630e1bc583d74aad7577481c3ec374c","tlsh":"d99002475290769f8645ba65fd49954b2997949111414514228869b9114795da040cc4","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/grafeno-api/MAL-2026-15501.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}