{"id":"MAL-2026-4390","summary":"Malicious code in @flowselections/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b28cf238827c035b4f3103aff9bf803421b7d16d1c7877d7e74c5fcd71f3283b)\nThe package exports a `supabase` client and `LoginPage` component wired to a hardcoded Supabase URL (`https://vmicscahrnzpmhagztmx.supabase.co`) and anon key with no env-var or prop override. In `dist/supabase/client.js` the URL is a literal constant, and `dist/components/layout/LoginPage.js` calls `supabase.auth.signInWithPassword({ email, password })` against that client. Any consumer that integrates the advertised `LoginPage`, `useAuth`, or `supabase` exports to gate access to their own application will silently send their end-users' email/password credentials, sign-up data, and profile reads/writes to the author-controlled Supabase tenant rather than the consumer's own backend. There is no documented opt-out or configuration surface. This is the silent-relay shape: caller-supplied data flows through the package's public API to a destination hardcoded by the author.\n","modified":"2026-05-27T00:31:54.735179319Z","published":"2026-05-19T23:30:06Z","withdrawn":"2026-05-26T21:28:12Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.8"],"id":"IN-MAL-2026-003298","import_time":"2026-05-26T05:50:22.626283538Z","modified_time":"2026-05-19T23:30:06Z","sha256":"10c8f363044768327f1f38a83c90a6d4b9d867f6c7f72512c5fcac35f4d6fdd9"},{"source":"amazon-inspector","versions":["1.0.9"],"id":"IN-MAL-2026-004188","import_time":"2026-05-26T05:52:06.490362712Z","modified_time":"2026-05-22T10:29:53Z","sha256":"b28cf238827c035b4f3103aff9bf803421b7d16d1c7877d7e74c5fcd71f3283b"},{"id":"IN-MAL-2026-003297","import_time":"2026-05-26T05:50:22.531639756Z","modified_time":"2026-05-19T23:30:06Z","sha256":"1755cea321d563069e1918466fcea382c6d58d9b2be7546c543cc094355d1b86","source":"amazon-inspector","versions":["1.0.8"]},{"modified_time":"2026-05-22T10:29:53Z","sha256":"78d0fb002f806ee13e259caafb457d0f9a8195d7a75d07f1fe5d6b866d13a2bf","source":"amazon-inspector","versions":["1.0.9"],"id":"IN-MAL-2026-004189","import_time":"2026-05-26T05:52:06.593930917Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@flowselections/core/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@flowselections/core/v/1.0.8"}],"affected":[{"package":{"name":"@flowselections/core","ecosystem":"npm","purl":"pkg:npm/%40flowselections%2Fcore"},"versions":["1.0.8","1.0.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@flowselections/core/MAL-2026-4390.json","indicators":{"domains":["34.2.16.104.in-addr.arpa"],"evidence_files":[{"sha256":"9e2e6357e1642f1b29851cbd67de35ffffd7fc571f62ad6fe80934a88e4df1f8","tlsh":"5901f16357414039112525e3020ed619d732d4bb3fe6c9e1706c0cb8bfa518bdbfd09a","path":"dist/supabase/client.js"}],"package_integrity":[{"filename":"core-1.0.9.tgz","hashes":{"sha1":"03b33a9cf3b0d90aae1e3bdc9e6ebae05eae42b2","sha512_sri":"sha512-KWQFnx8HvVbCFg9Eh4AdaSNpYmycE2WzbIH3hd6ZczQ5fFLJUpdSfWq9+wo7mLJJgGU5JdvqQDKM2/tw0aC/DA=="}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}