{"id":"MAL-2026-17528","summary":"Malicious code in tiny-viewport-unit-calc (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (34c221d8f8f0fedded27bfc22763912ffd96e9f3d1b2c08932e054ed418f493e)\nThe package ships thunderboltRegistry.js, a module that imports Node's child_process primitives and executes `whoami` plus repeated `ping` commands against external hostnames, with POST calls present in the same file. The pattern (whoami capture + repeated ping-based beacons + outbound POSTs) is host-reconnaissance and DNS/ICMP-channel exfiltration shape, directed from the installer's machine to an external endpoint. The behavior is unrelated to the package's advertised purpose (a trivial viewport-unit calculator) and provides no functionality to a consumer; its only effect is to leak host identity information off-host when the module is loaded or invoked.\n","modified":"2026-10-04T23:45:21.717390225Z","published":"2026-10-04T23:26:23Z","database_specific":{"malicious-packages-origins":[{"sha256":"34c221d8f8f0fedded27bfc22763912ffd96e9f3d1b2c08932e054ed418f493e","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020960","import_time":"2026-10-04T23:40:46.074034142Z","modified_time":"2026-10-04T23:26:23Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tiny-viewport-unit-calc/v/1.0.0"}],"affected":[{"package":{"name":"tiny-viewport-unit-calc","ecosystem":"npm","purl":"pkg:npm/tiny-viewport-unit-calc"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"thunderboltRegistry.js","sha256":"192a1662599b3707964325a0010418076db01e08e363f469c4d1ff2984167615","tlsh":"368120fef7d5f1b10a93b4285b7f2009e17366932d0898c1f94c96b22fb486404366f5"}],"package_integrity":[{"filename":"tiny-viewport-unit-calc-1.0.0.tgz","hashes":{"sha1":"8b008019810ef641cf5b6d0aa7797e02238aa746","sha512_sri":"sha512-/ETImFJIJZeuOhHJUcSJsQtZYhvJAm405CmnIyCrq6OKTzdZDwvnRwrxB+pakI67HWcSopMUHdJySx1Esfymfw=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tiny-viewport-unit-calc/MAL-2026-17528.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}