{"id":"MAL-2026-15687","summary":"Malicious code in @yuva2210/okx-poc-rce-impact (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1917fdda46d566300463afdd1087755e9cf50203f4997455f9ee888e01782124)\n@yuva2210/okx-poc-rce-impact@2.0.0 is a dependency-confusion proof-of-concept targeting OKX's internal namespace. The package's `package.json` declares a `preinstall` script that runs on `npm install` and executes `child_process.execSync` calls for `whoami`, `hostname`, `pwd`, and `id`, collecting installer host and user identifiers and writing them to `/tmp/okx-poc-rce-proof.json`. The package has no other functional content — `index.js` is empty — so the tarball's only effect on installation is to execute the reconnaissance payload on the installer's machine. Any developer or build system that inadvertently resolves an OKX-internal name to this public package runs arbitrary code at install time. The self-labeled 'harmless PoC' framing does not change the mechanism: unsolicited command execution and host-identifier collection fire automatically on `npm install`.\n","modified":"2026-09-04T01:00:06.295901554Z","published":"2026-08-24T16:34:29Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-01T11:17:26.679648626Z","modified_time":"2026-08-24T16:34:29Z","sha256":"a3b3b9c183ebf6f54dc431b511528972beb71ad492e38595ec816edc05041b7f","source":"reversing-labs","versions":["2.0.0"],"id":"RLMA-2026-05949"},{"sha256":"1917fdda46d566300463afdd1087755e9cf50203f4997455f9ee888e01782124","source":"amazon-inspector","versions":["2.0.0"],"id":"IN-MAL-2026-019392","import_time":"2026-09-04T00:45:55.301292249Z","modified_time":"2026-09-03T23:51:18Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@yuva2210/okx-poc-rce-impact/v/2.0.0"}],"affected":[{"package":{"name":"@yuva2210/okx-poc-rce-impact","ecosystem":"npm","purl":"pkg:npm/%40yuva2210/okx-poc-rce-impact"},"versions":["2.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"232129125fc5efb92891d8421839c15bf912df0c205b6a5df4ae9277a2a8986232dd3c","path":"package.json","sha256":"d3f1f932f67970bfcb5c94e8e2857e3b51eabc366a7d6f2ffe81a236cb2feafe"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-9gEUvBH6RnAcLdNEy2oCCZg5YbAhQ7wmRycYPNNpfjdV81ZvD5IJk5DDyVbSxEhCYlLlh3c/pEQJCakNDjPfzA==","sha1":"47a3971c7c810d82520fcec2a242f5de1fda62bf"},"filename":"okx-poc-rce-impact-2.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@yuva2210/okx-poc-rce-impact/MAL-2026-15687.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}