{"id":"MAL-2026-15512","summary":"Malicious code in jsb-adapter (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (368bba2e9d134a0d1ce565627644361ebe98bbf7bc2fd04812ff7137c300eaac)\npackage.json declares a dependency whose key (`jsb-adapter`) equals this package's own name and whose value is the bare HTTPS URL `https://repo.securityctrl.com/jsb-adapter` instead of a registry version range. On `npm install`, npm fetches whatever tarball that host currently returns, unpinned and with no integrity check, and runs any lifecycle scripts inside it — so the code executed on the installer is whoever controls `repo.securityctrl.com` at install time, not the published tarball. The shipped index.js is an inert stub, so the manifest line is the entire published payload. Aggravating shape: the dependency key matches the package's own name and the version `45.0.0` is implausibly high, consistent with dependency-confusion targeting an internal package of the same name.\n","modified":"2026-08-28T23:31:38.961541773Z","published":"2026-08-28T23:13:14Z","database_specific":{"malicious-packages-origins":[{"versions":["45.0.0"],"id":"IN-MAL-2026-019080","import_time":"2026-08-28T23:14:36.85337479Z","modified_time":"2026-08-28T23:13:14Z","sha256":"368bba2e9d134a0d1ce565627644361ebe98bbf7bc2fd04812ff7137c300eaac","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/jsb-adapter/v/45.0.0"}],"affected":[{"package":{"name":"jsb-adapter","ecosystem":"npm","purl":"pkg:npm/jsb-adapter"},"versions":["45.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"4de0c228491116b386d7195a1c3ac5dbf3928f5f2408bd09d2cb142c814f6b3b9fa35e","path":"package.json","sha256":"ad72e91e222b8675ae4744d66f1235b2c8546f024bb127aed35fbef0c735cce7"}],"package_integrity":[{"filename":"jsb-adapter-45.0.0.tgz","hashes":{"sha1":"9cee6ee2023e47d9d0c0a5ac071ca2f0be2d9d16","sha512_sri":"sha512-nNRz+aLF3maB9TDK5XNjt9bqSCe6mGFCOiqGkucMVnVV7ZIxdXszIJ+OLTahG0cAhg09CKtpuBy+M9lbKNgmnA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/jsb-adapter/MAL-2026-15512.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}