{"id":"MAL-2026-16326","summary":"Malicious code in byted-commerce-materials (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f777e32b4a6cbb7f91f7fcac050a02a73e356df1c87e7dcd985ea9172a3993da)\npackage.json declares both preinstall and postinstall running `node callback.js`, so the payload fires automatically on `npm install`. callback.js collects hostname, username, platform, cwd, home directory, network interfaces, uid/gid, CI/cloud provider fingerprints, and probes the working directory for credential files (.env,.npmrc,.yarnrc,.git/config,.docker/config.json, credentials, secrets.json). It also enumerates process.env keys and filters them against a broad credential-name regex set (token, secret, key, password, aws, azure, gcp, npm, ssh, private, credential, jwt, bearer, stripe, db, mysql, postgres, mongo, redis). The collected payload is POSTed to api.telegram.org via a hardcoded Telegram Bot API token and chat_id (1064260758). A secondary DNS-based side channel base64-encodes host/user/CI fields and issues a `dns.resolve` against a `\u003cencoded\u003e.dc-callback.example.com` subdomain as a fallback for environments that block HTTPS to Telegram. The package presents itself as a byted/commerce materials module and a `security research / dependency confusion PoC`; the self-label does not change that the traced behavior harvests installer host and credential reconnaissance and ships it off-host to attacker-controlled channels without consent.\n","modified":"2026-09-21T04:00:07.592297969Z","published":"2026-09-21T03:29:19Z","database_specific":{"malicious-packages-origins":[{"sha256":"f777e32b4a6cbb7f91f7fcac050a02a73e356df1c87e7dcd985ea9172a3993da","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020221","import_time":"2026-09-21T03:46:37.176180126Z","modified_time":"2026-09-21T03:29:19Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/byted-commerce-materials/v/1.0.0"}],"affected":[{"package":{"name":"byted-commerce-materials","ecosystem":"npm","purl":"pkg:npm/byted-commerce-materials"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"ae39c187820502961774874f3376f91f238a1d8027c6a1ca7b1fb9b641f7a683","tlsh":"90d1d6da21ab991115e162d6590e6c036849e0073f0db5e93e2c93a19fc9d3c93b37fb","path":"callback.js"}],"package_integrity":[{"hashes":{"sha1":"ef5890b740998fac00ef748880d8df2d732392ad","sha512_sri":"sha512-sB7tObISPcCc85cqkE9ACZjGSauPwTUqwEtemyhE+C4WIySciCXodrSkCm7yzM1vzlg1Fzs0AVC8hEdtb9NQBw=="},"filename":"byted-commerce-materials-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/byted-commerce-materials/MAL-2026-16326.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}