{"id":"MAL-2026-17314","summary":"Malicious code in test-supply-npm-lib-4 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268)\npackage.json declares a dependency sourced from a git URL (git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git) pinned to commit 0abd2c55e475f12f58fb67ac487db4c1b00cf597, rather than from the npm registry. On `npm install`, npm clones that GitHub repository and runs any lifecycle scripts it contains, including a `prepare` hook indicated by the dependency's name. The dependency source is an individual GitHub account (agustedone/...) unrelated to any established publisher, and the fetched code is not subject to npm registry review or integrity checks against a registry tarball. Whoever controls that GitHub repository controls code executed on the installer's machine at install time.\n","modified":"2026-09-30T06:00:05.224000342Z","published":"2026-09-30T01:47:02Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["3.3.3"],"id":"IN-MAL-2026-020791","import_time":"2026-09-30T02:52:56.663772057Z","modified_time":"2026-09-30T01:47:10Z","sha256":"4088f6f05dc6a2187563d3b6e47047d7206446a8642bb62d2cc2c27347418e70"},{"modified_time":"2026-09-30T01:47:02Z","sha256":"80bcbaa6379206627641c70dd25da3c3adfd51337f9a378223a6f8f13c8ba3ed","source":"amazon-inspector","versions":["3.3.4"],"id":"IN-MAL-2026-020790","import_time":"2026-09-30T02:52:56.544764263Z"},{"source":"amazon-inspector","versions":["3.3.6"],"id":"IN-MAL-2026-020820","import_time":"2026-09-30T05:44:17.304955595Z","modified_time":"2026-09-30T05:30:46Z","sha256":"3eae72a7bc74450d855cd61f154508a7b6e1419095c8d3c88c32f3e81b77b3af"},{"versions":["3.3.5"],"id":"IN-MAL-2026-020821","import_time":"2026-09-30T05:44:17.334402313Z","modified_time":"2026-09-30T05:30:56Z","sha256":"44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/test-supply-npm-lib-4/v/3.3.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/test-supply-npm-lib-4/v/3.3.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/test-supply-npm-lib-4/v/3.3.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/test-supply-npm-lib-4/v/3.3.5"}],"affected":[{"package":{"name":"test-supply-npm-lib-4","ecosystem":"npm","purl":"pkg:npm/test-supply-npm-lib-4"},"versions":["3.3.3","3.3.4","3.3.6","3.3.5"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-supply-npm-lib-4/MAL-2026-17314.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"48e05c60d6210c7728c129f0cc613443ff518c234464ad053793516dce491bb40fd63f","path":"package.json","sha256":"8d90884a76b25c576aecaa0b096d8c7c1d8d934e8c6ac6e11501bc18b6adfc06"}],"package_integrity":[{"hashes":{"sha1":"e350fa83bf9607ab65feda3190e2d7d1bc4fd99e","sha512_sri":"sha512-BhsR8kcp0u4pNt6yZ/RiP46Xt2hUNuBZreE1lghxVuCLPV3+CNO1lbgVLlaM27uxYEC4evcfDdVjK4nP+5tGSA=="},"filename":"test-supply-npm-lib-4-3.3.3.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}