{"id":"MAL-2026-15590","summary":"Malicious code in com.db.autobahn.notification-center-electron (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452)\npackage.json declares preinstall and postinstall lifecycle scripts that automatically run curl on `npm install` to send installer identity (`whoami`, `hostname`, `$PWD`, timestamp) as query-string parameters to a long-random-label third-party host (`da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com`) over plain HTTP. The package name (`com.db.autobahn.notification-center-electron`) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint.\n\n## Source: ossf-package-analysis (fe0ae07b99c275a092bcb2e4836aeb711a02f98def45f54f91bcf5ba38873807)\nThe OpenSSF Package Analysis project identified 'com.db.autobahn.notification-center-electron' @ 88.88.2 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-31T18:31:22.153973113Z","published":"2026-08-30T02:04:57Z","database_specific":{"malicious-packages-origins":[{"sha256":"fe0ae07b99c275a092bcb2e4836aeb711a02f98def45f54f91bcf5ba38873807","source":"ossf-package-analysis","versions":["88.88.2"],"import_time":"2026-08-30T23:14:56.250461164Z","modified_time":"2026-08-30T02:04:57Z"},{"source":"amazon-inspector","versions":["88.88.2"],"id":"IN-MAL-2026-019173","import_time":"2026-08-31T17:16:14.223440079Z","modified_time":"2026-08-31T16:49:01Z","sha256":"07cca8298b9df97ebc9a5c6a7d3457aab14d13397a9ad40dabe62ec46a5d35aa"},{"source":"amazon-inspector","versions":["88.88.1"],"id":"IN-MAL-2026-019311","import_time":"2026-08-31T18:22:29.77536951Z","modified_time":"2026-08-31T18:03:24Z","sha256":"4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/com.db.autobahn.notification-center-electron/v/88.88.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/com.db.autobahn.notification-center-electron/v/88.88.1"}],"affected":[{"package":{"name":"com.db.autobahn.notification-center-electron","ecosystem":"npm","purl":"pkg:npm/com.db.autobahn.notification-center-electron"},"versions":["88.88.2","88.88.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.db.autobahn.notification-center-electron/MAL-2026-15590.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"com.db.autobahn.notification-center-electron-88.88.2.tgz","hashes":{"sha1":"b84ba1bb07c2dde3a5a13055b0afc96b23ec2e03","sha512_sri":"sha512-EXvIVSAPub1QUp+04VznGRBpByQi7gHeHkmboSyXTsh14i8Fe9fQvsdFTBP3tXCfr+ylnwIUl0U+khMvE+fMKg=="}}],"evidence_files":[{"sha256":"c16336aeff434c2a12a373001cef40de06552558af13ffc42fc3d95919445659","tlsh":"a2f07d38743614733dc59a2c2cc58a0bba619d870b6d34455b87c84837ae3726aba209","path":"package.json"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}