{"id":"MAL-2026-15924","summary":"Malicious code in real-router-telemetry (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (78bc9af22f0b3feafc2dbd863d7ce4b9ba26418ab58e87bc231123004a40a450)\nPackage ships telemetry.js, an obfuscated module (string-array accessor pattern hiding identifiers and the destination) that reads host identity (hostname, username, cwd, platform, arch, memory, cpu info), executes `cat /etc/os-release` and `ps aux`, reads `.env` from the current working directory via fs.readFileSync, and POSTs the collected JSON to https://webhook.site/e32d3b8a-a5df-40cc-ae60-7a8343b581e4, an anonymous request-capture endpoint unrelated to any declared publisher. `.env` files in a developer's cwd typically contain API keys, tokens, and other credentials that do not belong to this package. package.json declares a postinstall hook (`node -e \"require('./index.js')\"`); index.js in this build is a stub (declaring version 1.0.1 while the manifest is 1.0.4) that does not currently require telemetry.js, so the shipped payload is staged but not wired into the install-time entry point in this version. The combination of an obfuscated host-and-secret exfil module targeting an anonymous webhook collector, mismatched version metadata, and an install-time hook aimed at the package's own entry point indicates a malicious package.\n","modified":"2026-09-04T07:00:08.517843404Z","published":"2026-09-04T06:34:52Z","database_specific":{"malicious-packages-origins":[{"sha256":"339c7fb3c40f724b7ec7c2ac3c67068b03f9d871ec65876913795cff3c2d9537","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-019635","import_time":"2026-09-04T06:53:31.333102704Z","modified_time":"2026-09-04T06:35:01Z"},{"modified_time":"2026-09-04T06:34:52Z","sha256":"78bc9af22f0b3feafc2dbd863d7ce4b9ba26418ab58e87bc231123004a40a450","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-019634","import_time":"2026-09-04T06:53:31.237576474Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/real-router-telemetry/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/real-router-telemetry/v/1.0.4"}],"affected":[{"package":{"name":"real-router-telemetry","ecosystem":"npm","purl":"pkg:npm/real-router-telemetry"},"versions":["1.0.1","1.0.4"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/real-router-telemetry/MAL-2026-15924.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"telemetry.js","sha256":"e8f5e8befa52fba91746b3698890453ced8c24d7dcf7accceff2c349e12169fe","tlsh":"a24141527ee41e781312a07ed3a33422e393862ab8c16991f09de54c9bcdf05d4e32f4"},{"path":"package.json","sha256":"462bf33890820506ca6e7ed62fa59bb8cc1c777675fe08c7e01d9258d28d6ceb","tlsh":"90d0a7700d20963714d407f75db3810756738d7b410cb908179751af80de6b759fe62d"}],"package_integrity":[{"filename":"real-router-telemetry-1.0.1.tgz","hashes":{"sha1":"82ba9311a284ee31f9ac08def9c69438aa16771b","sha512_sri":"sha512-4Hz7cRSSn054Qn15Q+6gpdND3WnqIaieRPP+cALDomozzAY3TA3YhBsDUtGPujdjaAVjH8UREzuUGkIMbJRFww=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}