{"id":"MAL-2026-15853","summary":"Malicious code in @quantixfinance/supabase (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (957f7218e15bdaaead1d170d28c2b67949c808b52985e36ec2f993573af1312f)\nThe package's preinstall lifecycle script enumerates process.env and collects any variable whose name matches credential-shaped substrings (key, secret, token, pass, mnemonic, seed, private, wallet, api, rpc, infura, alchemy, supabase, database), attaches hostname, cwd, and node version, and POSTs the JSON payload to a hardcoded remote host written as the decimal integer 759017974 (which resolves to 45.63.10.182) on port 61289. The integer form of the destination host defeats plain-text IOC scanning. The package's index.js is a non-functional stub that exports a no-op createClient returning empty results, confirming the library body is cover and the package exists solely to run the install-time credential stealer. The scoped name resembles a private/internal organization scope, consistent with a dependency-confusion delivery shape.\n","modified":"2026-09-03T16:30:07.571105463Z","published":"2026-09-03T15:51:15Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-03T15:51:15Z","sha256":"957f7218e15bdaaead1d170d28c2b67949c808b52985e36ec2f993573af1312f","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-019365","import_time":"2026-09-03T16:19:42.822588906Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@quantixfinance/supabase/v/1.0.0"}],"affected":[{"package":{"name":"@quantixfinance/supabase","ecosystem":"npm","purl":"pkg:npm/%40quantixfinance/supabase"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"8e21ba4af5bcf3b641a252b450cbc021a97fa40323c189a76b7c41d5ff468dc65634bb","path":"preinstall.js","sha256":"5ba35e7025a373dac1380e610b797be1612a10b86f792fe5118e4f25ee688686"},{"path":"index.js","sha256":"50a07ab9bd3fd927808afaef993f22c954813a77f57365c448dfe18037cc4aae","tlsh":"7ba0024912d522fd115f91639638c4c265d8f089059b8632834c86de445444e7248055"}],"package_integrity":[{"filename":"supabase-1.0.0.tgz","hashes":{"sha1":"8d360bb2a3d10f14abbad6e4bec5fda4a89cc5b4","sha512_sri":"sha512-qsI7zIJdEWJr6YM5se5HQzcuKNnwVGttPxRISp3sDgxllvjDW2MbVaa3JJi0ajjAbUW+crMHmdPW6RYc25PToQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@quantixfinance/supabase/MAL-2026-15853.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}