{"id":"MAL-2026-17515","summary":"Malicious code in monitoring-agent (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (703c1e796904571c9f0d08a4769a5f7e25a646483b4a66815a6ddc420ae0ecee)\nThe package exports an Express middleware (`monitor()`) advertised as a monitoring tool. On every response finish, the middleware POSTs the inbound HTTP request to a hardcoded author-controlled host at https://backend-cybersecuritydashboard.onrender.com/api/events. The payload explicitly extracts `req.body.password`, `req.body.username`, and `req.body.email` as dedicated fields alongside the full request headers, body, query string, and route params. The destination URL is not configurable by the caller — the only caller-supplied value is an apiKey. Any Express application that mounts this middleware will silently forward its end users' plaintext credentials and complete request payloads to this third-party Render host on every request. The package.json uses placeholder author metadata (`Your Name`) with no repository or homepage, and the exfiltration destination is unrelated to any disclosed publisher.\n","modified":"2026-10-04T23:45:16.973079930Z","published":"2026-10-04T23:26:54Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-04T23:26:54Z","sha256":"703c1e796904571c9f0d08a4769a5f7e25a646483b4a66815a6ddc420ae0ecee","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-020963","import_time":"2026-10-04T23:40:46.361161141Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/monitoring-agent/v/1.0.1"}],"affected":[{"package":{"name":"monitoring-agent","ecosystem":"npm","purl":"pkg:npm/monitoring-agent"},"versions":["1.0.1"],"database_specific":{"indicators":{"package_integrity":[{"filename":"monitoring-agent-1.0.1.tgz","hashes":{"sha512_sri":"sha512-NJOemjl/hq2ehMts1chz2YsuDr4O37FhNYQprI6QFB+JuZs2+9FYWFHA6/7xFjqSlm5+a/bGAvh5D1uD7y3kKg==","sha1":"f0555042009d4f3708fd80859b7d39ab95f91e82"}}],"evidence_files":[{"tlsh":"0c21bd1f4583105405bae7a88661491de222c727d90e8d12be7c857d4fbc00160c5fec","path":"monitor.js","sha256":"4457e192153bd97382a9656f01ee8e3a8cab4105c583b7b88a42016d70784d5a"},{"tlsh":"5af09720c2205a2b03d935681d955143b6a28e8b12647d0873cf623c4bcf03f3afe22c","path":"package.json","sha256":"a0722ffac099d2a117fd72c7505c3c7bec5ecd9cd9e04abfc7e80f5bf6f1d475"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/monitoring-agent/MAL-2026-17515.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}