{"id":"MAL-2026-15548","summary":"Malicious code in 2fasecretkey (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (776f74322ea1fc554c37d759c1a038d8647779b1e2b3ce51e3fd4c865118e094)\nOn npm install, the package's postinstall script performs an HTTP GET to http://185.14.92.233:7777/p.js, writes the response to a temp file, and launches it through a detached wscript.exe invocation of a VBS stager that runs the installer's Node executable against the downloaded payload with the window hidden (WScript.Shell.Run flag 0, detached, stdio ignored). The fetch uses plain HTTP against a hardcoded bare IP with no version pinning, hash check, or signature verification, and the executed code is not shipped in the tarball. The package's advertised purpose is a TOTP helper, which has no functional need to fetch or execute remote code at install time. The hidden-window VBS launcher conceals execution from the installing user.\n","modified":"2026-08-29T02:30:11.879422868Z","published":"2026-08-29T01:55:51Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-019126","import_time":"2026-08-29T02:22:19.589583976Z","modified_time":"2026-08-29T01:56:06Z","sha256":"268483d850acafa895551342533e35ff8aa2f37a4c3bbd7b9403c05d0fe29406","source":"amazon-inspector","versions":["1.1.4"]},{"versions":["1.1.3"],"id":"IN-MAL-2026-019125","import_time":"2026-08-29T02:22:19.478852679Z","modified_time":"2026-08-29T01:55:58Z","sha256":"5fbd991a433280c543872057a7c0c3517a339c5076a31cb3b02ba828d23765cb","source":"amazon-inspector"},{"versions":["1.1.2"],"id":"IN-MAL-2026-019124","import_time":"2026-08-29T02:22:19.387013733Z","modified_time":"2026-08-29T01:55:51Z","sha256":"776f74322ea1fc554c37d759c1a038d8647779b1e2b3ce51e3fd4c865118e094","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/2fasecretkey/v/1.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/2fasecretkey/v/1.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/2fasecretkey/v/1.1.2"}],"affected":[{"package":{"name":"2fasecretkey","ecosystem":"npm","purl":"pkg:npm/2fasecretkey"},"versions":["1.1.4","1.1.3","1.1.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/2fasecretkey/MAL-2026-15548.json","indicators":{"evidence_files":[{"path":"package.json","sha256":"721fd1fcc494e706c009beb2006fd2a2d557861c457aa9a79939ccdceb56c786","tlsh":"0011ef6cbe78ab2751d4a2f1e61f4103b223cd030180694c935705cd9bed297993fd6c"}],"package_integrity":[{"hashes":{"sha1":"b2e456392a1937d06853fe3ed94422ab75d5dc00","sha512_sri":"sha512-RPOQP9NZ/N50ke32VdRjiFYCvmnHTk3bRO1GFbeu6D1fGFaN8XXTlXy3YDLkfgm44nk6b/r9tr2yRtBjtY924g=="},"filename":"2fasecretkey-1.1.4.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}