{"id":"MAL-2026-16313","summary":"Malicious code in test1gg234 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dd57f799e0797ede7d18d6a36dd05c31c34d21b4e45d554730a8d08dd310cf73)\nThe package declares both preinstall and postinstall lifecycle hooks that execute index.js, which issues a plaintext HTTP GET to the hardcoded bare IP 128.199.122.145 with the package name in the query string. The beacon fires unconditionally on npm install, confirming to the operator of that host that the package was resolved and installed on the target machine. The package has no other functionality: an empty description, an inflated version (99.99.99), and a manifest that declares a lookalike dependency `requests` alongside a duplicate capitalized `Dependencies` key referencing `request` — the shape of a dependency-confusion probe rather than a functional library.\n","modified":"2026-09-21T03:30:16.602528065Z","published":"2026-09-21T03:22:52Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020207","import_time":"2026-09-21T03:24:21.352380542Z","modified_time":"2026-09-21T03:22:52Z","sha256":"dd57f799e0797ede7d18d6a36dd05c31c34d21b4e45d554730a8d08dd310cf73","source":"amazon-inspector","versions":["99.99.99"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/test1gg234/v/99.99.99"}],"affected":[{"package":{"name":"test1gg234","ecosystem":"npm","purl":"pkg:npm/test1gg234"},"versions":["99.99.99"],"database_specific":{"indicators":{"package_integrity":[{"filename":"test1gg234-99.99.99.tgz","hashes":{"sha1":"db6609bb78fc0dafdb00f26425eab73ca87fa543","sha512_sri":"sha512-C9MxN8EDSMrnwJTigOWAlXF8L0Fy0MJt+q/2//CgLEzD2soAopA9I2KGYk3Eu+VMilLAz+eCPQkutCOiQbcRQg=="}}],"evidence_files":[{"path":"index.js","sha256":"516803efbc40266c03927a1c42c8f96f6dd312f547b3b630f2de5f4bc15230da","tlsh":"a5c08cc2a382f39486f14986a529161a230df170b9fc44bae34c23ad488396d51a3ac1"},{"sha256":"8c3341690162c43530f6615a782d7ac7c45b176e791cf1bf1698fd06ff131a91","tlsh":"a9e09261cc509a7310fc13e968791b07b1626f2b42685c4f34f3b48d66a2126449ef29","path":"package.json"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test1gg234/MAL-2026-16313.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}