{"id":"MAL-2026-16345","summary":"Malicious code in starbucks-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f42de3e225b6f8d6be04fbf613ae4d17458626c92f2cfe1bf1b4476fe132e761)\nThe package's package.json declares a preinstall script that runs callback.js on npm install. callback.js collects os.hostname(), os.userInfo(), os.platform(), the current working directory, and a timestamp, then enumerates process.env and selects keys matching /token|secret|key|pass|auth|api|aws/i (up to 10 entries). The collected data is POSTed via https.request to https://api.telegram.org/bot\u003cBOT_TOKEN\u003e/sendMessage using a hardcoded Telegram bot token and chat_id (bot 8636277735, chat_id 1064260758). The name mimics a legitimate vendor SDK but the package's only behavior is install-time reconnaissance and exfiltration of installer/build-host identity and credential-shaped environment variable names to an attacker-controlled Telegram channel — a dependency-confusion recon payload.\n\n## Source: ossf-package-analysis (cbea0cf6cf424cbaa524691f90c075f11c4c5265e941abdeab442a53ccbb0caf)\nThe OpenSSF Package Analysis project identified 'starbucks-sdk' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-09-21T05:30:06.331553156Z","published":"2026-09-20T00:45:28Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-020224","import_time":"2026-09-21T03:46:37.476637222Z","modified_time":"2026-09-21T03:29:54Z","sha256":"f42de3e225b6f8d6be04fbf613ae4d17458626c92f2cfe1bf1b4476fe132e761","source":"amazon-inspector"},{"modified_time":"2026-09-20T00:45:28Z","sha256":"cbea0cf6cf424cbaa524691f90c075f11c4c5265e941abdeab442a53ccbb0caf","source":"ossf-package-analysis","versions":["1.0.0"],"import_time":"2026-09-21T05:19:22.270910164Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/starbucks-sdk/v/1.0.0"}],"affected":[{"package":{"name":"starbucks-sdk","ecosystem":"npm","purl":"pkg:npm/starbucks-sdk"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"5b6efb0aaa20cb1687147d3267a1d7f6cc7ce8f99a5f66ab96980c085524e689","tlsh":"8f1154ec51f5c45b56ad54e3b097b8082597d0113d06f8a0f8ae02995fc60d4c931ffc","path":"callback.js"}],"package_integrity":[{"hashes":{"sha1":"12d8b489bad07e22e5bbc4e8c1673e213ee09412","sha512_sri":"sha512-hFrxbA5IbwwoVuFFC4Y3u24dzn2h9OW/aVly/W4o+0AQIL5bbhIXkaMLZsORVYR72eieFKRRgrk/88l/bQIn3w=="},"filename":"starbucks-sdk-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/starbucks-sdk/MAL-2026-16345.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}