{"id":"MAL-2026-15598","summary":"Malicious code in verify-contract-ethers (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ec7cfabb396e93e034caeb560ea029e3ca2bde784b8c713d5f8941a2b621dd36)\nThe package ships a single bin entry (bin/cli.js) that, when invoked, runs `whoami` and POSTs the package name, username, hostname, and platform to a hardcoded Cloudflare Workers callback at https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The bin is registered under the name `fuels-typegen` while the package itself is published as `verify-contract-ethers`, a name/bin mismatch consistent with typosquatting or dependency-confusion against fuels-typegen / verify-contract. The package's declared description openly states its purpose is to POST package name and whoami to an out-of-band callback, and no legitimate functionality is present beyond that beacon.\n\n## Source: ossf-package-analysis (dd92ae4a5555d9abe274ad50e627402e6fcba1b9486f0f565dd2a11920417532)\nThe OpenSSF Package Analysis project identified 'verify-contract-ethers' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-31T17:30:12.808452732Z","published":"2026-08-30T08:40:44Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-30T23:14:55.508435771Z","modified_time":"2026-08-30T08:40:44Z","sha256":"dd92ae4a5555d9abe274ad50e627402e6fcba1b9486f0f565dd2a11920417532","source":"ossf-package-analysis","versions":["1.0.0"]},{"id":"IN-MAL-2026-019184","import_time":"2026-08-31T17:16:15.233354795Z","modified_time":"2026-08-31T16:50:35Z","sha256":"ec7cfabb396e93e034caeb560ea029e3ca2bde784b8c713d5f8941a2b621dd36","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/verify-contract-ethers/v/1.0.0"}],"affected":[{"package":{"name":"verify-contract-ethers","ecosystem":"npm","purl":"pkg:npm/verify-contract-ethers"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"7bb9e78369c5381ad92a3997176d860469dcbd35fef2d80123dadf978eb15649","tlsh":"94112dea50f553b0bfa22c944d2f50003297c7673c09fcc0faac0359af4ea5c41325a8","path":"bin/cli.js"},{"tlsh":"bfe061508b211de314dc5ef11c3a96175221e86b106c7d6632d7330d43492721237379","path":"package.json","sha256":"152edeab11c2356848d2f9c007d45e6756884fbfc6ca403f131a82d87c459ba7"}],"package_integrity":[{"filename":"verify-contract-ethers-1.0.0.tgz","hashes":{"sha1":"0c02b8afe28c67e47a8b11d5f29662ee1668e268","sha512_sri":"sha512-1+gCTH00KByKs/77VMf0cOwMY4lJH4WErHsS6AWBHhUYifuxB0TQSdMdv3diNkr8HZdxPMz4m/9HwfKRX7C9rA=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/verify-contract-ethers/MAL-2026-15598.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}