{"id":"MAL-2026-15681","summary":"Malicious code in @grab-food/order-sdk-web (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aa9b56bb1d69dc16b6095faea196af99809ad805b400a3c6b5499f896c8d74c2)\nPackage published under a scope impersonating the Grab food-ordering brand with no real functionality (index.js exports an empty object). Its sole dependency, grab-food-order-sdk-web-core@49.9.9, is pinned to a tarball URL at https://registry.grivy-packages.com/ — a lookalike domain outside the npm registry. Installing @grab-food/order-sdk-web@49.9.9 causes npm to fetch and install code from that attacker-controlled host into the installer's node_modules, bypassing npm registry inspection and running whatever lifecycle scripts and code the fetched tarball contains. This is a dependency-chain dropper: the visible package is a hollow lure, and the actual payload arrives via the non-registry dependency URL.\n","modified":"2026-09-04T01:00:06.671572172Z","published":"2026-08-24T16:24:13Z","database_specific":{"malicious-packages-origins":[{"source":"reversing-labs","versions":["49.9.9"],"id":"RLMA-2026-05869","import_time":"2026-09-01T11:17:24.924656563Z","modified_time":"2026-08-24T16:24:13Z","sha256":"a824327f01d7927827541106fb6f567872ad3bfc3bc6cdd722a02093bea5e2f9"},{"versions":["49.9.9"],"id":"IN-MAL-2026-019390","import_time":"2026-09-04T00:45:55.144738436Z","modified_time":"2026-09-03T23:51:00Z","sha256":"aa9b56bb1d69dc16b6095faea196af99809ad805b400a3c6b5499f896c8d74c2","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@grab-food/order-sdk-web/v/49.9.9"}],"affected":[{"package":{"name":"@grab-food/order-sdk-web","ecosystem":"npm","purl":"pkg:npm/%40grab-food/order-sdk-web"},"versions":["49.9.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"e901b93cab00df135a6145b0404106866e69465f0b42bd0caf5313aa93063d6ecea92e","path":"package.json","sha256":"f991b879a26b02975bac8c1f4ed609fcb3d7f88c09d56fd21fc354373ca0e7ea"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@grab-food/order-sdk-web/MAL-2026-15681.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}