{"id":"MAL-2026-17292","summary":"Malicious code in @selfpentest/bin-confusion (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (40a68543ca2674f2b90d89dd52516736791b7886d617c694d89dd3135e7499f3)\npackage.json registers a `bin` entry named `npm` pointing at npm.js, deliberately colliding with the core npm CLI. Once this package is installed as a dependency, any `npm...` invocation in a consuming project's scripts resolves via node_modules/.bin to this shim, executing the shipped code before (or instead of) the real npm. npm.js contains a `steal()` routine that reads process.env.HOME, process.env.SECRET, and the first 30 bytes of ~/.ssh/known_hosts, concatenates them into a query string, and issues a fetch GET to http://localhost:1337/. The destination is loopback in this build, but the collected data (installer SSH known_hosts contents and environment secrets) is packaged into a functioning exfiltration primitive that fires whenever the shadow `npm` shim is invoked from the installer's build scripts. The scope name (`@selfpentest`) and README frame this as a demonstration, but the shipped tarball is a working bin-shadow + credential-read + network-send chain against installers who add it as a dependency.\n","modified":"2026-09-29T22:31:17.391047329Z","published":"2026-09-29T22:12:09Z","database_specific":{"malicious-packages-origins":[{"sha256":"40a68543ca2674f2b90d89dd52516736791b7886d617c694d89dd3135e7499f3","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020685","import_time":"2026-09-29T22:18:23.828093319Z","modified_time":"2026-09-29T22:12:09Z"},{"import_time":"2026-09-29T22:18:23.876033932Z","modified_time":"2026-09-29T22:12:27Z","sha256":"b8eee4f9fa3dd0a476be7853709b1d126d84b0cc51b9a298d822038cb7c05c80","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020687"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@selfpentest/bin-confusion/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@selfpentest/bin-confusion/v/1.0.0"}],"affected":[{"package":{"name":"@selfpentest/bin-confusion","ecosystem":"npm","purl":"pkg:npm/%40selfpentest/bin-confusion"},"versions":["1.0.1","1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"bin-confusion-1.0.1.tgz","hashes":{"sha1":"7253b6b5cecfbdc5fec4eca9e304ed25f68bb86a","sha512_sri":"sha512-+jfVd+b1JHd8zttc8dXEdmFOoR2hmFLkQGXSmZwCDG7XdBr4d5W2adh6eOZJWZ8FTMr/A41pSA16ABSKLNxGZQ=="}}],"evidence_files":[{"path":"package.json","sha256":"57e36195d9df49781c8fd45bf2f25f79950a80c0564fc2d90399397529b0c699","tlsh":"a0e0c2174e12246314e819651c39417bb52a8f6b285ebd652bffa20c92cd3bb643564c"},{"path":"npm.js","sha256":"f82f3e8a084d7d4c833daf350c1ae17534841c6d540f138fe573a5dedfed572b","tlsh":"4a41004620f11a3886b222a3779b24033afbd0a73215cca475dc8671df5af758261dfa"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@selfpentest/bin-confusion/MAL-2026-17292.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}