{"id":"MAL-2026-16117","summary":"Malicious code in etoro-cashout (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1)\nThe package's preinstall.js lifecycle script runs on npm install and executes host reconnaissance commands (whoami, ipconfig/ip addr, directory listings of C:\\ and /, tasklist/ps, and a full environment-variable dump via set/env) and POSTs the collected output over plain HTTP to a hardcoded remote server at 209.126.81.147, using path segments under a canary token 'etoro-nuget-verify1f8eaa57a875'. The package name 'etoro-cashout' at version 99.0.2, the eToro-branded canary, and the beacon path shape are consistent with a dependency-confusion probe targeting an internal eToro registry: any build environment that resolves this public name executes the exfiltration on install. Data leaving the installer includes hostname, username, working directory, filesystem listings, running processes, and the full process environment, which on CI systems routinely contains cloud credentials, registry tokens, and API keys.\n","modified":"2026-09-11T18:45:05.112500793Z","published":"2026-09-10T04:45:58Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-10T04:45:58Z","sha256":"a35bbd75e3cc742fd88d59bcbb64858df0474505b5d6f93f10e8c727c718e129","source":"amazon-inspector","versions":["999.0.0"],"id":"IN-MAL-2026-019915","import_time":"2026-09-10T05:18:06.257486475Z"},{"id":"IN-MAL-2026-019996","import_time":"2026-09-11T18:21:31.906581633Z","modified_time":"2026-09-11T17:55:21Z","sha256":"a0d8b123f09da5d5d7e0c5f90590e52f5a02d5f1da0b52b4eb5cebd7ecb28071","source":"amazon-inspector","versions":["99.0.0"]},{"modified_time":"2026-09-11T17:55:29Z","sha256":"c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1","source":"amazon-inspector","versions":["99.0.2"],"id":"IN-MAL-2026-019997","import_time":"2026-09-11T18:21:31.965819313Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/etoro-cashout/v/999.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/etoro-cashout/v/99.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/etoro-cashout/v/99.0.2"}],"affected":[{"package":{"name":"etoro-cashout","ecosystem":"npm","purl":"pkg:npm/etoro-cashout"},"versions":["999.0.0","99.0.0","99.0.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-+oObK225egLxDtxuG7nwvQMvj7+AiKoi7cMQ1rVzqXSNbFE2uQFDFClsPw6xPt/GpoVCnWUT3t/jwft9Nw80sA==","sha1":"6be0db8f77a1da1981745fd01e3519c5b6de0965"},"filename":"etoro-cashout-999.0.0.tgz"}],"evidence_files":[{"sha256":"bee47062733940943fd3a66654f0258135fd62911674304ccac11a43226b5f58","tlsh":"ebe027f4118ca6683ccc01c4636b191ed4dfc705bcdec8c04a55d78587b15f1d6115f0","path":"preinstall.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-cashout/MAL-2026-16117.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}