{"id":"MAL-2026-4362","summary":"Malicious code in @arbocollab/arbo-web-people (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3f007c3da95aa64e4c2ed5b51b736900ddc444499f2f678d749603fab516a0c3)\nThe published tarball ships `npmjs.npmrc` containing a live `npm_`-prefixed authToken for `registry.npmjs.org` scoped to `@arbocollab`. `package.json` declares `\"files\": [\"*\"]` and `.npmignore` does not exclude `npmjs.npmrc`, so every installer receives the credential. The package.json `publish:lib` script references this same file via `--userconfig=npmjs.npmrc`, confirming it is the maintainer's real publish credential rather than a stub. Any installer or anyone who downloads the tarball can use this token to publish arbitrary malicious versions under the `@arbocollab` scope, pivoting into a supply-chain attack against all downstream consumers of any package in that scope. No install-time hooks are present; the harm is the credential redistribution itself. Remediation: revoke the token immediately, unpublish/deprecate affected versions, remove `npmjs.npmrc` from the published tarball, and add it to `.npmignore`/`files` allowlist.\n","modified":"2026-05-27T00:32:01.042316450Z","published":"2026-05-19T19:07:53Z","withdrawn":"2026-05-26T21:14:22Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-004624","modified_time":"2026-05-25T10:38:13Z","versions":["0.26.3-alpha.13"],"source":"amazon-inspector","sha256":"3f007c3da95aa64e4c2ed5b51b736900ddc444499f2f678d749603fab516a0c3","import_time":"2026-05-26T05:52:58.258142836Z"},{"import_time":"2026-05-26T05:52:53.909955945Z","id":"IN-MAL-2026-004589","modified_time":"2026-05-25T06:21:44Z","versions":["0.26.3-alpha.9"],"source":"amazon-inspector","sha256":"4821627bbaf9dd52acb4f81cd41314885366cee188c4a4a1f280df73eb237afa"},{"id":"IN-MAL-2026-003256","modified_time":"2026-05-19T19:07:53Z","versions":["0.26.3-alpha.7"],"source":"amazon-inspector","sha256":"7eabee413f8b1629aed91fce8717e416307c0cfe94c035180e99c1a2cbd17978","import_time":"2026-05-26T05:50:18.271220734Z"},{"versions":["0.26.3-alpha.10"],"source":"amazon-inspector","sha256":"91da50a4adf630e58c7d161164d7ffdd01d5f6bbe3f8265acff32aeabef9d44b","import_time":"2026-05-26T05:52:54.312117589Z","id":"IN-MAL-2026-004592","modified_time":"2026-05-25T06:38:42Z"},{"modified_time":"2026-05-26T11:01:59Z","versions":["0.26.3-alpha.15"],"source":"amazon-inspector","sha256":"2dc551980e00305aca3a1a7047ecaf4e65b69aa9ef4dcd6ca489a2d828ab1a88","import_time":"2026-05-26T13:32:46.305010097Z","id":"IN-MAL-2026-004901"},{"source":"amazon-inspector","sha256":"d59e5635dbfbe63e57949b98ea9df0b8a601dbeb017c1a535879d016bb648f20","import_time":"2026-05-26T13:32:46.175698146Z","id":"IN-MAL-2026-004899","modified_time":"2026-05-26T10:45:57Z","versions":["0.26.3-alpha.14"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@arbocollab/arbo-web-people/v/0.26.3-alpha.13"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@arbocollab/arbo-web-people/v/0.26.3-alpha.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@arbocollab/arbo-web-people/v/0.26.3-alpha.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@arbocollab/arbo-web-people/v/0.26.3-alpha.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@arbocollab/arbo-web-people/v/0.26.3-alpha.15"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@arbocollab/arbo-web-people/v/0.26.3-alpha.14"}],"affected":[{"package":{"name":"@arbocollab/arbo-web-people","ecosystem":"npm","purl":"pkg:npm/%40arbocollab%2Farbo-web-people"},"versions":["0.26.3-alpha.13","0.26.3-alpha.9","0.26.3-alpha.7","0.26.3-alpha.10","0.26.3-alpha.15","0.26.3-alpha.14"],"database_specific":{"indicators":{"package_integrity":[{"filename":"arbo-web-people-0.26.3-alpha.13.tgz","hashes":{"sha1":"6574da6feb7b799a5800d0cfdd789b0a414b37c1","sha512_sri":"sha512-mf8oLFq2JfLc8J/bTVWNjh/1XwX4tOzbaMUGmJYlFhXwxtp4SwuKAoBDDk5ZmwNPfNw7yeHb3+9mwMVQUhTWUQ=="}}],"evidence_files":[{"path":"npmjs.npmrc","sha256":"3fd0ea889836389cf540294ee0deb2af8c070683c235ad46b1854c27ab75dd9a","tlsh":"d7c09b7f4d1e990367e0d5dd8c40b4154eaa44c34fef46d2f3650fdc49819c2302681b"},{"tlsh":"8721722ac8c84e0321985a54bc284222d776125b68e07e853bdf12ac4f8e6af317e10d","path":"package.json","sha256":"57369a1191684be202de5a2d48c8e7b6861f64072c9ddc4daf6e47c9c96cbddd"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@arbocollab/arbo-web-people/MAL-2026-4362.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}