{"id":"MAL-2026-17502","summary":"Malicious code in botmaker-cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa)\nOn npm install, postinstall.js collects the installer's hostname, username, current working directory, architecture, platform, and network interface list (including private IPs) and POSTs them as JSON to the hardcoded host telemetry-edge.net at /api/v1/telemetry over HTTPS with certificate validation disabled (rejectUnauthorized: false). The same postinstall script reads the HTTP response body, parses it as JSON, and passes the response's `exec` field to child_process.execSync with a 30-second timeout, granting whoever controls telemetry-edge.net arbitrary shell command execution as the installing user on every machine that runs `npm install`. The package's index.js is an inert stub containing only `module.exports = { version: '0.1.19' }` and a comment directing users to a different scoped package (`@botmaker.org/botmaker-cli`), indicating this unscoped name is a lookalike lure whose sole operative payload is the install-time beacon-and-exec channel.\n","modified":"2026-10-04T23:45:19.914071095Z","published":"2026-10-04T23:17:21Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.19"],"id":"IN-MAL-2026-020904","import_time":"2026-10-04T23:40:40.315999962Z","modified_time":"2026-10-04T23:17:21Z","sha256":"86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/botmaker-cli/v/0.1.19"}],"affected":[{"package":{"name":"botmaker-cli","ecosystem":"npm","purl":"pkg:npm/botmaker-cli"},"versions":["0.1.19"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/botmaker-cli/MAL-2026-17502.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"d58662b9c4fa3a7af9a2adb9484e90de88d32e6c34f87f8e60d02d2abd64f299","tlsh":"401132e116f1527096f7d4ee5917d41a6213d0177a0aede0b99c42246fcd43c60f2af6"},{"sha256":"99b6c35fbe4cc2f8b4a6f37f5c02ece9e55c1d93b29a3b9c202b1f2eae4bdc9c","tlsh":"2dc09b171e1f2b276956cf52a34f56442f545570246b4d9835d7950c874580d4505185","path":"index.js"}],"package_integrity":[{"filename":"botmaker-cli-0.1.19.tgz","hashes":{"sha1":"feb6eb6158732c49c32737a33e840bf140d02b8d","sha512_sri":"sha512-Lfb0zjFkmqHO4JI2oLe7MeIyrAgdueGqm4p0BxozJl6eTNYOVWfoDN7uzcpKwI8IgCfAKTiqwi38s7OUtAqEbw=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}