{"id":"MAL-2026-15563","summary":"Malicious code in vitest-chalk-pro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4718de971af33ad02b8945e1b981e30d1decbf9c7d1006f37a641cd822156f0e)\nvitest-chalk-pro@10.0.7 declares a postinstall hook (node lib/utils/index.js) that spawns a detached, silenced child process running lib/utils/smtp-connection/index.js. That child uses axios to GET https://api.jsonbin.io/v3/b/6a62bc86da38895dfe879659 and passes the returned `cookie` field to `new Function('require',...)(require)`, executing attacker-controlled JavaScript on the installer's machine at every `npm install`. The fetched content is opaque and mutable — the operator of the jsonbin document can rotate the payload at any time. The child is spawned with `detached: true`, `stdio: ['ignore','ignore','ignore']`, and `unref()` so it continues running after npm install returns and produces no output. The package name suggests a vitest/chalk utility, but `main` is a verbatim copy of nodemailer's entrypoint (author metadata `Andris Reinman`, ETHEREAL_* environment variables, references to api.nodemailer.com), an unrelated facade that disguises the dropper.\n","modified":"2026-08-29T02:30:11.901509897Z","published":"2026-08-29T02:12:51Z","database_specific":{"malicious-packages-origins":[{"versions":["10.0.7"],"id":"IN-MAL-2026-019132","import_time":"2026-08-29T02:22:20.25800621Z","modified_time":"2026-08-29T02:12:51Z","sha256":"4718de971af33ad02b8945e1b981e30d1decbf9c7d1006f37a641cd822156f0e","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/vitest-chalk-pro/v/10.0.7"}],"affected":[{"package":{"name":"vitest-chalk-pro","ecosystem":"npm","purl":"pkg:npm/vitest-chalk-pro"},"versions":["10.0.7"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"e96ebeb43c6f0eda1f353dbeed62ab183db5922adcc6a0f95c4f7521b6535f3a","tlsh":"0dd0a78432a6656e21fa2585562620095053c6304d48f052b18467f11c504da6e61bf1","path":"lib/utils/smtp-connection/index.js"},{"path":"lib/utils/index.js","sha256":"9fb27c30f484650bb4a39f65a03fbccdc0b9b5f1cb84700ca73ee8893c66e06e","tlsh":"dae0686a23533738a034cbc1da30ce3b258b8020b365a0e0f00c406a2bc72c406ea8da"},{"sha256":"ce7e2c44c05eee343f56f5b77c6ed1e0af9173dd80936497632fdbe5e6f673be","tlsh":"7041a511cd678ce3369829ed68685183a420c00fcc1ab86db35c528c4f8e99f76b8a6d","path":"package.json"}],"package_integrity":[{"filename":"vitest-chalk-pro-10.0.7.tgz","hashes":{"sha1":"b1c724713b36bc9fca7d029174711cd5ff7f39da","sha512_sri":"sha512-FXztpbVAWQiodqrWbe8ikbvG0TC7ExYby51y23sK9fDN0ibV3TrIYINi/oXtbUjnpq2eLQXz+0t+lNyue8IkwQ=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vitest-chalk-pro/MAL-2026-15563.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}