{"id":"MAL-2026-15571","summary":"Malicious code in grafeno-billing (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (72306b800994fea3aa6c6d12e137657ffe70ec9ac6c44abfe3ceaa547ef8e5c6)\ngrafeno-billing@1.0.0 is a stub package whose only substantive code is a preinstall lifecycle hook. On npm install, preinstall.js enumerates process.env, filters keys matching AWS|TOKEN|KEY|SECRET|PASS|API, concatenates them with hostname and username, base64-encodes the result, and sends it via curl GET to http://216.126.236.46/r.php. On non-Windows hosts the same script also launches an interactive bash reverse shell to 216.126.236.46:4444 via /dev/tcp, giving the operator of that endpoint command execution on the installer's machine. The shipped index.js is a one-line stub returning a fake createInvoice result, with no real billing functionality, confirming the package exists solely to deliver the install-time attack.\n","modified":"2026-08-29T23:30:10.918682561Z","published":"2026-08-29T23:10:56Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019151","import_time":"2026-08-29T23:14:43.781322054Z","modified_time":"2026-08-29T23:10:56Z","sha256":"72306b800994fea3aa6c6d12e137657ffe70ec9ac6c44abfe3ceaa547ef8e5c6"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/grafeno-billing/v/1.0.0"}],"affected":[{"package":{"name":"grafeno-billing","ecosystem":"npm","purl":"pkg:npm/grafeno-billing"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"preinstall.js","sha256":"1765463bd5af82667f6ff06326bf4635c047ab619fdec5385f9c7ae4669d6aec","tlsh":"ccf0ddb551a972b4996289d0e2d2c47761fbd6123521fad0da9800ea4e9225048f35ee"},{"sha256":"388851d2b8fa3990677cb78fbf525925200b7d5bf581bf69bbcc667c1a25b3a4","tlsh":"c0a002e9e592f25e41649113b197d68a55d056900158d061078a956c85c1e74408d884","path":"index.js"}],"package_integrity":[{"filename":"grafeno-billing-1.0.0.tgz","hashes":{"sha1":"7a3ce768c41c4dcf2c378e51a43a48aa07dba207","sha512_sri":"sha512-j7nqHZcqqoptsEtvumEKQXF+DpyuXNld1j2em/gyLDDj+XUUXiXjmKdbFsXZx76A/t6Rqoxyk3A4vGPHySw/Rw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/grafeno-billing/MAL-2026-15571.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}