{"id":"MAL-2026-16283","summary":"Malicious code in @shared-web/assets (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e8fd9342e97dc9f655a994fe1091125f717cbfa7b89aa6a2333662ad23ad6771)\nThe package runs an install lifecycle script (`node index.js`) and also executes `./lib/core.js` on require. That code collects `os.userInfo().username`, `os.hostname()`, and `process.cwd()` and issues a DNS `resolve4` for a label chain of the form `\u003cpkg\u003e.\u003cuser\u003e.\u003chost\u003e.\u003ccwd\u003e.\u003cts\u003e.oob.algamil7x.xyz`, exfiltrating installer identity and working-directory information over DNS to an attacker-controlled domain. The destination host and the `os`/`dns`/`process` module names are obfuscated in `lib/c5df9a.js` and `lib/b4ce8f.js` using char-code byte arrays (`String.fromCharCode`) and loaded via `module.constructor._load` instead of plain `require`, concealing both the APIs and the C2 destination. The obfuscation and DNS-label-encoded channel are inconsistent with the package's presentation as a shared web assets helper.\n","modified":"2026-09-18T14:30:07.102572954Z","published":"2026-09-18T14:06:59Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-18T14:18:03.285829276Z","modified_time":"2026-09-18T14:06:59Z","sha256":"e8fd9342e97dc9f655a994fe1091125f717cbfa7b89aa6a2333662ad23ad6771","source":"amazon-inspector","versions":["9.9.10"],"id":"IN-MAL-2026-020181"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@shared-web/assets/v/9.9.10"}],"affected":[{"package":{"name":"@shared-web/assets","ecosystem":"npm","purl":"pkg:npm/%40shared-web/assets"},"versions":["9.9.10"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"fef7a5e2ff57547938b250275a83e792509a3df0e221d336e87894d77d16f1f8","tlsh":"13f07d29b393c08fa7e086d0360a03d18459c3c0d7cf81d5f7bc4a87800e7d1ca85a59","path":"lib/core.js"},{"path":"lib/c5df9a.js","sha256":"80f0c2df46bf1abf098b1c1082f089f4790edbca0156dd8fdb3fe08ed3ccc5d3","tlsh":"e9e0201b319fe14fa6d85eb73f17c5dacc420900e31d8ad9fa2d4787206a046c0c0775"}],"package_integrity":[{"filename":"assets-9.9.10.tgz","hashes":{"sha1":"65631e9bc1f67d1eaff2019a68fc618cea25453e","sha512_sri":"sha512-AIBHpr6Yyh9SwA7NjF7GHB6XG7sqgTwKTPvFlbvZS/Y9EPm2NCWItNXvyOvtKaQMLYXlq5zQsgqPUCPWuhJmNQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@shared-web/assets/MAL-2026-16283.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}