{"id":"MAL-2026-17652","summary":"Malicious code in @ziedzzz/demo-canary (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e6350184f3eabc17d37726cdd71ea97666cef28b2e1c125cffeb56e7c474b8dd)\nOn `npm install`, the package's declared postinstall script executes index.js, which collects a host fingerprint (hostname, username, home directory, cwd, platform/arch/OS release, CPU model, memory, network interfaces including MAC/OUI, process info) and enumerates process.env for variable names matching TOKEN|SECRET|KEY|PASS|AWS_|GCP_|AZURE_|SSH|GIT|NPM|DOCKER. The collected data is transmitted via HTTPS GET to the hardcoded third-party endpoint telegrambot-aebk.onrender.com/ping. The behavior fires automatically on install without opt-in and discloses the installer's host identity and credential-variable inventory to an author-controlled destination.\n","modified":"2026-10-08T04:00:04.907562376Z","published":"2026-10-08T03:37:45Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-021112","import_time":"2026-10-08T03:50:28.66592176Z","modified_time":"2026-10-08T03:37:45Z","sha256":"e6350184f3eabc17d37726cdd71ea97666cef28b2e1c125cffeb56e7c474b8dd","source":"amazon-inspector","versions":["1.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ziedzzz/demo-canary/v/1.0.0"}],"affected":[{"package":{"name":"@ziedzzz/demo-canary","ecosystem":"npm","purl":"pkg:npm/%40ziedzzz/demo-canary"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@ziedzzz/demo-canary/MAL-2026-17652.json","indicators":{"evidence_files":[{"sha256":"1ad2ad5b251c088ccc219c5de1e11c0f5166e7a76e250ca13a50f15d326de018","tlsh":"2ed172b12da0543435b5d33d6b064123ea15bb133601e1a6bcbc72962fee864c169efe","path":"index.js"}],"package_integrity":[{"hashes":{"sha1":"80c3675dbe6e2d7f45f86b6772d7dba1ae77bf35","sha512_sri":"sha512-d2nQDcRSLNTz2NRlhzARTOKNPtNa7kQZ+EsnM15fye6k7wBbmOHD/RQtVBp/VJvLBbH1Aw14BwF43SAMld90oA=="},"filename":"demo-canary-1.0.0.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}