{"id":"MAL-2026-16119","summary":"Malicious code in etoro-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d31819832ff4b43fc9bc7bcd9f3439f71902802331ba6df3c3964c47765397e1)\nThe preinstall lifecycle script in etoro-client@999.0.0 unconditionally sends the installer's hostname, OS username, and current working directory to the hardcoded bare-IP endpoint http://209.126.81.147/etoro-depconf-poce346552f776f/npm/\u003chost\u003e/\u003cuser\u003e/\u003ccwd\u003e over plain HTTP at `npm install` time. The package name combined with the implausibly high 999.0.0 version and the `depconf` path token indicate a dependency-confusion attack targeting an internal `etoro-client` package: publishing a high-version public namesake so that misconfigured resolvers pull this artifact instead of the private internal one. The preinstall beacon then confirms successful landing on a target and identifies the host, user, and build path.\n","modified":"2026-09-10T05:30:11.582610981Z","published":"2026-09-10T04:44:04Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["999.0.0"],"id":"IN-MAL-2026-019910","import_time":"2026-09-10T05:18:06.01162967Z","modified_time":"2026-09-10T04:44:04Z","sha256":"d31819832ff4b43fc9bc7bcd9f3439f71902802331ba6df3c3964c47765397e1"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/etoro-client/v/999.0.0"}],"affected":[{"package":{"name":"etoro-client","ecosystem":"npm","purl":"pkg:npm/etoro-client"},"versions":["999.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-client/MAL-2026-16119.json","indicators":{"package_integrity":[{"filename":"etoro-client-999.0.0.tgz","hashes":{"sha512_sri":"sha512-janSI3eUewR+HHF0elLHbrmPAiH9xFUcjW7et2/ZgqpaBTqn6YBEtmHwjE58Wue6h6AclF6FkaNc4hOdxtge6g==","sha1":"9a0ffabaec316f783ce3631e8ca1f025d94d4a60"}}],"evidence_files":[{"sha256":"bee47062733940943fd3a66654f0258135fd62911674304ccac11a43226b5f58","tlsh":"ebe027f4118ca6683ccc01c4636b191ed4dfc705bcdec8c04a55d78587b15f1d6115f0","path":"preinstall.js"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}