{"id":"MAL-2026-15595","summary":"Malicious code in generate-schema-viem (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (82b43ea1e723ebd0c0ef5c4cd564b106089f9b5f9fd119dcac26dc1e130a14bf)\nPackage publishes as `generate-schema-viem` but exposes a bin named `generate-schema-ethers` (a dependency-confusion / typosquat shape against the `generate-schema-*` namespace). On CLI invocation, `bin/cli.js` executes `whoami`, reads `os.hostname()` and platform, and POSTs `{pkg, whoami, hostname, platform}` to the hardcoded endpoint `https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9`. The manifest's own description self-labels the package as an OOB callback. Installer identity is leaked to an external attacker-controlled endpoint whenever the tool is invoked on a developer machine or CI runner.\n\n## Source: ossf-package-analysis (6300576c16b112520e6a4cde256e38ce14736ec575b8c94e58a0a9163c7dad78)\nThe OpenSSF Package Analysis project identified 'generate-schema-viem' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-31T17:30:11.694261869Z","published":"2026-08-30T07:59:20Z","database_specific":{"malicious-packages-origins":[{"source":"ossf-package-analysis","versions":["1.0.0"],"import_time":"2026-08-30T23:14:55.816051728Z","modified_time":"2026-08-30T07:59:20Z","sha256":"6300576c16b112520e6a4cde256e38ce14736ec575b8c94e58a0a9163c7dad78"},{"id":"IN-MAL-2026-019179","import_time":"2026-08-31T17:16:14.737254419Z","modified_time":"2026-08-31T16:49:50Z","sha256":"82b43ea1e723ebd0c0ef5c4cd564b106089f9b5f9fd119dcac26dc1e130a14bf","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/generate-schema-viem/v/1.0.0"}],"affected":[{"package":{"name":"generate-schema-viem","ecosystem":"npm","purl":"pkg:npm/generate-schema-viem"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/generate-schema-viem/MAL-2026-15595.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"bin/cli.js","sha256":"7bb9e78369c5381ad92a3997176d860469dcbd35fef2d80123dadf978eb15649","tlsh":"94112dea50f553b0bfa22c944d2f50003297c7673c09fcc0faac0359af4ea5c41325a8"},{"tlsh":"05e061508a201db314cc5ef12c3aa5175131d8571178fc7532df631d9349571017b37d","path":"package.json","sha256":"f23feca4d93248ab69c00d5158cbbe7c0049c09b0874a43015fadbd499bf9923"}],"package_integrity":[{"filename":"generate-schema-viem-1.0.0.tgz","hashes":{"sha1":"8fb9d86b9620229e21ef1709e8722a74d25e7e37","sha512_sri":"sha512-KgZjs7v/T61g09tc/grBYNECe4XmEvM0X4+OexYuNkidcv6X1de1mQPrRWoFW2YkMu1okvjed2Aad5FjwxNoOQ=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}