{"id":"MAL-2026-16352","summary":"Malicious code in @baanx/blockchain-config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0b6dec4d715e2863e7f55749d6d2a390926f3f2f1df62e4de223c6acc818632d)\nThe package runs a bootstrap from both its install lifecycle script (`node index.js`) and its main module that invokes an obfuscated probe. The probe reads `os.userInfo().username`, `os.hostname()`, and the basename of `process.cwd()`, concatenates them with a static tag (`bxcfg`) and a timestamp, and performs a `dns.resolve4` lookup against `\u003ctag\u003e.\u003cuser\u003e.\u003chost\u003e.\u003ccwd\u003e.\u003cts\u003e.oob.algamil7x.xyz`, exfiltrating installer identity over DNS to a non-first-party domain unrelated to the claimed baanx publisher. The exfil host and the `os`/`dns`/`userInfo`/`hostname`/`cwd`/`resolve4` API references are hidden in `String.fromCharCode`/hex-decoded byte arrays in `probe/impl.js` and sibling files `e9c3a6.js` / `f0d4b7.js`, and the `os` and `dns` modules are loaded through `module.constructor._load` with decoded name arrays to defeat static analysis. Behavior fires automatically on `npm install` and on `require('@baanx/blockchain-config')`.\n","modified":"2026-09-21T17:45:06.302309713Z","published":"2026-09-21T17:15:43Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-21T17:15:43Z","sha256":"0b6dec4d715e2863e7f55749d6d2a390926f3f2f1df62e4de223c6acc818632d","source":"amazon-inspector","versions":["9.9.11"],"id":"IN-MAL-2026-020264","import_time":"2026-09-21T17:38:31.737937334Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@baanx/blockchain-config/v/9.9.11"}],"affected":[{"package":{"name":"@baanx/blockchain-config","ecosystem":"npm","purl":"pkg:npm/%40baanx/blockchain-config"},"versions":["9.9.11"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@baanx/blockchain-config/MAL-2026-16352.json","indicators":{"evidence_files":[{"path":"runtime/support/telemetry/probe/impl.js","sha256":"74cabd564f982cad05f3366bbd8dfccdb1c61f1517cb401e1e657444e668d0f8","tlsh":"23119c5ab253d08f23c04695391c43e1482dc2d097dd51d1bbbc168ba2cd7914ad3a76"},{"path":"runtime/support/telemetry/probe/f0d4b7.js","sha256":"8b334e1d6cd445ed52f797ed4e123d25f5be174ebb2700b15795c8034ec9d6e6","tlsh":"8ce0201725aff14fa6e85ea72f17c4dbc8820a00a21c4bd9fa0d0687206e007c0c0771"}],"package_integrity":[{"hashes":{"sha1":"66951b67868ab6e5a2bf12634c382583336facf7","sha512_sri":"sha512-jYnQ4ncfvYXq6clch3ETiW/fZCpfEO2x+okCsa6VfHFBrLZNh7k/+rmLSC9kPfn8HrJEOPWBKytqlb7MqSqkvw=="},"filename":"blockchain-config-9.9.11.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}