{"id":"MAL-2026-17498","summary":"Malicious code in @kibt/www-nuxt-i18n (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5ab1895c73507311b9efd31e40015529d9d7735c87e50cf3b714e6e520205ec4)\nThe package is a stub whose index.js exports a Proxy returning no-op functions for every property access, allowing bundlers that import any member of the expected real package to succeed. The package.json declares a postinstall script `node beacon.cjs`, and index.js also loads the same beacon at require() time. beacon.cjs collects installer host metadata — os.hostname(), the install directory (__dirname), process.cwd(), and process.version — and POSTs it to the hardcoded plain-HTTP bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The destination is not affiliated with any legitimate publisher, the package provides no real functionality, and an in-source comment frames successful installs as evidence of a hit — matching the canonical dependency-confusion / namesquat validator shape where host identity is reported back to the operator to confirm which internal environments resolved the attacker-controlled scoped name.\n","modified":"2026-10-04T23:45:17.915046805Z","published":"2026-10-04T23:18:25Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-04T23:40:41.723166935Z","modified_time":"2026-10-04T23:19:22Z","sha256":"485839cc6750a2751283c1a9453c7b28bf58a29ca316cdb5c4e3027afc2e731b","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-020917"},{"id":"IN-MAL-2026-020915","import_time":"2026-10-04T23:40:41.516929707Z","modified_time":"2026-10-04T23:19:05Z","sha256":"ec95d08e30fac283e7a552bcf9bd48a3d3059a6c92ea5f6b846ed1bd3dccc402","source":"amazon-inspector","versions":["1.0.0"]},{"sha256":"f85cda0eb18d988d0bc6c5f066f764e86756851f34449942c7ca858a46b22577","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-020911","import_time":"2026-10-04T23:40:41.138097956Z","modified_time":"2026-10-04T23:18:25Z"},{"import_time":"2026-10-04T23:40:41.231560328Z","modified_time":"2026-10-04T23:18:34Z","sha256":"5ab1895c73507311b9efd31e40015529d9d7735c87e50cf3b714e6e520205ec4","source":"amazon-inspector","versions":["0.0.1"],"id":"IN-MAL-2026-020912"},{"source":"amazon-inspector","versions":["1.1.0"],"id":"IN-MAL-2026-020913","import_time":"2026-10-04T23:40:41.327549809Z","modified_time":"2026-10-04T23:18:43Z","sha256":"98b7faf73b0fb9d003258f882b09b23728db415cdf504436021d32f6ac791a29"},{"source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020914","import_time":"2026-10-04T23:40:41.424700819Z","modified_time":"2026-10-04T23:18:56Z","sha256":"c3dd2ab4972bdf73b521c63a38dd410378d0ad84f6485ededddd423e19e4ac7f"},{"import_time":"2026-10-04T23:40:41.932811285Z","modified_time":"2026-10-04T23:19:44Z","sha256":"cf82f32b9ae316d7d4931838da5479339785b611adc42d220bd65feca5bdd8ee","source":"amazon-inspector","versions":["3.0.0"],"id":"IN-MAL-2026-020919"},{"sha256":"d89b7fb5a53b101194ba86edae564e7cbd573f51001004f536e8b1e6a2d98962","source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-020916","import_time":"2026-10-04T23:40:41.612444927Z","modified_time":"2026-10-04T23:19:15Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/0.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/0.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/3.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@kibt/www-nuxt-i18n/v/2.0.1"}],"affected":[{"package":{"name":"@kibt/www-nuxt-i18n","ecosystem":"npm","purl":"pkg:npm/%40kibt/www-nuxt-i18n"},"versions":["99.0.1","1.0.0","0.1.0","0.0.1","1.1.0","1.0.1","3.0.0","2.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@kibt/www-nuxt-i18n/MAL-2026-17498.json","indicators":{"evidence_files":[{"path":"beacon.cjs","sha256":"029af10dabcfa3ab85da4ce16ad46e6b67aef25ad5f7cee8615f0387379e5a3b","tlsh":"d9316feba8f1a008aaaa7498c54f0409f27bf0068401af54f95c82919f6193c33fa8dc"},{"tlsh":"e0d02e20ca201e2324c82ee20e2a2a0a65a20d2b01043c083387402c06acb3728ff23f","path":"package.json","sha256":"cb48910951c419b943131d8a4ab0cd62d1e7bb54141356426318d8fef287a2aa"}],"package_integrity":[{"filename":"www-nuxt-i18n-99.0.1.tgz","hashes":{"sha1":"71cdd733dc6440b86bf6f5d772b30a93332b5f25","sha512_sri":"sha512-QyK3xbP2bFLNT+7CcVEoSlR6BBbCd8DNrgez0PLfkNHI0TUp8oIP6842KscQtk7/bI1mTibg+Z65X1pQ7+aNmQ=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}