{"id":"MAL-2026-3676","summary":"Malicious code in 88q (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cb830829cae1605ff7626653a2470db03cd5a5aab98b3f0a7f5912eaf244561b)\nThe main entrypoint index.js runs an IIFE at require time that monkey-patches the global console.warn and console.error methods. After the override, every subsequent console.warn/console.error call in the host process causes the first argument to be JSON-stringified, URL-encoded, and sent via HTTPS GET to https://api.telegram.org/bot\u003ctoken\u003e/sendMessage with hardcoded chat_ids (-1001161709623 for warn, -1001433099398 for error). The package exports only the undefined return value of the IIFE and provides no legitimate API, meaning its sole effect is the silent installation of a global diagnostic-log exfiltration channel. Any installer whose code runs console.warn/console.error after loading this module will leak log contents — which frequently include error stack traces, DB error messages, internal file paths, auth failures, and other sensitive runtime data — to an attacker-controlled Telegram chat. Additional unreachable files (t.js, o.js, jq.js) contain author-owned Cloudflare, MapQuest, and Firebase credentials; these are author self-harm and not the basis for blocking, but reinforce that the package is a personal project with a clear installer-targeted backdoor in the main module.\n","modified":"2026-05-13T20:20:34.524509Z","published":"2026-05-12T07:44:50Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-05-12T19:03:07Z","sha256":"0daa9fcdb5d5f8808d593664e1b459e30660c8749d7c37dbe39fad309d53c2ec","source":"amazon-inspector","versions":["1.1.1"],"id":"IN-MAL-2026-002489","import_time":"2026-05-13T20:10:57.9763455Z"},{"source":"amazon-inspector","versions":["1.4.8"],"id":"IN-MAL-2026-002503","import_time":"2026-05-13T20:10:59.355144775Z","modified_time":"2026-05-12T19:03:07Z","sha256":"46f300e5c1c263dd0307e51ce4c6146c3bb6154eb4b45093d7dfc21378b90ac0"},{"modified_time":"2026-05-12T19:03:07Z","sha256":"a5c54735e94f20ebb4b49b4177b53ba59461d01d657179d7ce74bc3372f74bf5","source":"amazon-inspector","versions":["1.2.6"],"id":"IN-MAL-2026-002494","import_time":"2026-05-13T20:10:58.529581793Z"},{"id":"IN-MAL-2026-002500","import_time":"2026-05-13T20:10:59.065627908Z","modified_time":"2026-05-12T19:03:07Z","sha256":"b51245ca46fd91fd3c5ead2e0ac6c307c79426ec89192cc4b8de4a370901baf8","source":"amazon-inspector","versions":["1.3.6"]},{"id":"IN-MAL-2026-002487","import_time":"2026-05-13T20:10:57.844622729Z","modified_time":"2026-05-12T19:03:07Z","sha256":"c7c50f85652ce401d24ae482911088ba99a9c0bbc20c557b8cce7d07559b59b1","source":"amazon-inspector","versions":["1.0.2"]},{"versions":["1.2.4"],"id":"IN-MAL-2026-002495","import_time":"2026-05-13T20:10:58.601814292Z","modified_time":"2026-05-12T19:03:07Z","sha256":"d98117e6352bdd43b27d69a1e157fbfd0792fc629f42f910b7aed480f6c50ac3","source":"amazon-inspector"},{"id":"IN-MAL-2026-002504","import_time":"2026-05-13T20:10:59.404523488Z","modified_time":"2026-05-12T19:03:07Z","sha256":"dfd483376dbe937b7e7944ef32e50ac3fae4144f8f2825b3eb2abfbd6009f10f","source":"amazon-inspector","versions":["1.4.9"]},{"sha256":"181f84c5f19279c4de19e1dcc4ab8968c1a96dc20ad4801e555fb55b45144c48","source":"amazon-inspector","versions":["1.1.4"],"id":"IN-MAL-2026-002490","import_time":"2026-05-13T20:10:58.153834761Z","modified_time":"2026-05-12T19:03:07Z"},{"id":"IN-MAL-2026-002501","import_time":"2026-05-13T20:10:59.166706918Z","modified_time":"2026-05-12T19:03:07Z","sha256":"471e567a6621adb423bb511da078fc447bf20839bbc219d9e91d21216427e20f","source":"amazon-inspector","versions":["1.4.6"]},{"id":"IN-MAL-2026-002498","import_time":"2026-05-13T20:10:58.919194208Z","modified_time":"2026-05-12T19:03:07Z","sha256":"514aa6166f2c533d4eb01618bf699f05b80f71182021bd11125e6bfa47b3451a","source":"amazon-inspector","versions":["1.3.3"]},{"modified_time":"2026-05-12T19:03:07Z","sha256":"6da9a1199176e2f5ccc8b7a2ad8b199fdf2ee3256282fb65d693fc0c36e621a8","source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-002488","import_time":"2026-05-13T20:10:57.894271951Z"},{"versions":["1.3.5"],"id":"IN-MAL-2026-002499","import_time":"2026-05-13T20:10:58.992137941Z","modified_time":"2026-05-12T19:03:07Z","sha256":"ad5fecc5879a38dfd2ab65870607b5b901efcf12588e4ac884eef9302291fb07","source":"amazon-inspector"},{"modified_time":"2026-05-12T19:03:07Z","sha256":"bb8c30d7cc35d6f8f3a8d4827195bad9da5cb74720dc385bcfec156ccd7e4464","source":"amazon-inspector","versions":["1.2.3"],"id":"IN-MAL-2026-002492","import_time":"2026-05-13T20:10:58.282331085Z"},{"id":"IN-MAL-2026-002493","import_time":"2026-05-13T20:10:58.40043631Z","modified_time":"2026-05-12T19:03:07Z","sha256":"fbfaaf434d15398e9b0c645145489909ea3ff45fa8e155dfee7d830e3a4c7758","source":"amazon-inspector","versions":["1.2.5"]},{"sha256":"d00b5a2b45065c4989659e04a1216635187c72b794e741a3600b16ee71f14939","source":"amazon-inspector","versions":["1.4.7"],"id":"IN-MAL-2026-002502","import_time":"2026-05-13T20:10:59.29018237Z","modified_time":"2026-05-12T19:03:07Z"},{"source":"amazon-inspector","versions":["1.2.7"],"id":"IN-MAL-2026-002496","import_time":"2026-05-13T20:10:58.73002355Z","modified_time":"2026-05-12T19:03:07Z","sha256":"73d938c4e6ec0dc716f1e2f02365307ffeb88d1253ef924f3da6dae795ae9839"},{"id":"IN-MAL-2026-002497","import_time":"2026-05-13T20:10:58.836818538Z","modified_time":"2026-05-12T19:03:07Z","sha256":"cb830829cae1605ff7626653a2470db03cd5a5aab98b3f0a7f5912eaf244561b","source":"amazon-inspector","versions":["1.3.2"]},{"sha256":"f24a3b6ad6eacf11a818ca5e6d4f366d8bee9a4c348f474a2dfafcb2c7f8b80c","source":"amazon-inspector","versions":["1.1.5"],"id":"IN-MAL-2026-002491","import_time":"2026-05-13T20:10:58.222393067Z","modified_time":"2026-05-12T19:03:07Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.4.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.2.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.3.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.2.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.4.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.4.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.3.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.3.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.2.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.2.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.4.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.2.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.3.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/88q/v/1.1.5"}],"affected":[{"package":{"name":"88q","ecosystem":"npm","purl":"pkg:npm/88q"},"versions":["1.1.1","1.4.8","1.2.6","1.3.6","1.0.2","1.2.4","1.4.9","1.1.4","1.4.6","1.3.3","1.0.7","1.3.5","1.2.3","1.2.5","1.4.7","1.2.7","1.3.2","1.1.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"urls":["https://api.telegram.org/bot848707422:AAGliik4xQpOpKOIP4qVss7BASJ3Ssw4uyA/sendMessage?chat_id=${x}&text=${encodeURIComponent(z"],"domains":["api.telegram.org"],"evidence_files":[{"path":"index.js","sha256":"d1b881c129a1d8cc02851630fba441b73648681a2eced6710711c6f3663df3b3","tlsh":"3c11dc852efe90714c8a7015955b9107a5e5ea3b120cec20b64c82f02f31c92cbb2b89"},{"tlsh":"16421f60a895b4732f12d26034ec6a1b9366525f2ca4fc21b9ce444f2f5cfeb2642ed4","path":"t.js","sha256":"0296ff2815758a68d3763c6e4af0a1c74ad58b965d97dea77abf98770b7a4669"}],"package_integrity":[{"filename":"88q-1.1.1.tgz","hashes":{"sha1":"a3016309be328fc5459d91fc566c517cb1443b4d","sha512_sri":"sha512-1oWBMIsXMqbyVKJ2pdl6tXJwbIn53jvHqHwWMbTVfx7DGH6T5OCmKD095U3b1s74dlpdAvAAoVpGlpWJT3nMjw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/88q/MAL-2026-3676.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}