{"id":"MAL-2026-16542","summary":"Malicious code in zeal-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f7a4b9b4fcb0a48aa3602fc7bc865eff738f8ab42a4c9e56ea31e70b0b6b826f)\ncanary.js in zeal-utils@0.0.0 collects host reconnaissance data (os.hostname(), os.userInfo(), process.platform, cwd, node version) and POSTs it to the hardcoded external endpoint https://npm-canary.aveliscare.com. The destination is not a package registry or documented vendor endpoint and is unrelated to any legitimate utility functionality implied by the package name. The package name and near-empty version (0.0.0) combined with a single script that beacons system identification to an author-controlled host is consistent with a dependency-confusion or canary-token style beacon that identifies internal build environments where the package resolves.\n","modified":"2026-09-30T01:00:07.620182182Z","published":"2026-09-22T17:46:49Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-22T17:46:49Z","sha256":"9f91f6dc4415c8175df7186c2a51dfb42c82b7a9a7272b370d398ea0cc2d063c","source":"reversing-labs","versions":["0.0.0"],"id":"RLMA-2026-10816","import_time":"2026-09-24T09:21:36.788333765Z"},{"id":"IN-MAL-2026-020746","import_time":"2026-09-30T00:52:54.254341365Z","modified_time":"2026-09-30T00:31:23Z","sha256":"f7a4b9b4fcb0a48aa3602fc7bc865eff738f8ab42a4c9e56ea31e70b0b6b826f","source":"amazon-inspector","versions":["0.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/zeal-utils/v/0.0.0"}],"affected":[{"package":{"name":"zeal-utils","ecosystem":"npm","purl":"pkg:npm/zeal-utils"},"versions":["0.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-DpDEt0CoOQ+i1WBRgIKh2MWqMZ4u5U5k/LKGHPwVeLH+HntYbIHkRVdC5pFLNyioh83HxrYGH45twtw6Z2TJvw==","sha1":"e1c8208ac4a05ec633c74e2cd0197abf13732de9"},"filename":"zeal-utils-0.0.0.tgz"}],"evidence_files":[{"tlsh":"acd1d86613f052762b8206b4591f00979736e027722aa170f5af92143f4a6bc87f3deb","path":"canary.js","sha256":"313f6afebeb44640d7df7a1995d0958bed918ecf2be8f171d4fbfe8dcab91f1d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zeal-utils/MAL-2026-16542.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}