{"id":"MAL-2026-4409","summary":"Malicious code in @nutui/nutui-react-taro (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (71ad42f4bfd953311c2d69f622cc6e8d5193a8852ac0bbc9ea0781ac6b651390)\nThe package's `postinstall.js` invokes `execSync('npm-usage-stats disable')` and `execSync('npm-usage-stats', { stdio: 'inherit' })`. The `npm-usage-stats` bin is provided by `@jmfe/npm-usage-stats-tool`, which is declared in `package.json` `optionalDependencies` pinned to `\"latest\"` (a mutable tag, not a fixed version or commit). On every `npm install`, npm resolves whatever code is currently published to that tag and the postinstall runs that code on the installer's machine with inherited stdio. Because the executed bytes are not shipped in this tarball, not version-pinned, and not hash-verified, the maintainer of the separate `@jmfe/npm-usage-stats-tool` package (or anyone able to publish to it) gains arbitrary code execution on every installer of `@nutui/nutui-react-taro@3.0.21-cpp` at install time. The off-channel `-cpp` version tag — which deviates from upstream `@nutui/nutui-react-taro` semver — and the `@jmfe` scope indirection (distinct from `@nutui`) compound the provenance concern: installers consenting to a UI component library do not consent to running an unrelated, mutable telemetry binary fetched from a different scope.\n","modified":"2026-05-27T00:31:58.137021988Z","published":"2026-05-20T15:08:09Z","withdrawn":"2026-05-26T21:41:23Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-003577","import_time":"2026-05-26T05:50:53.576663736Z","modified_time":"2026-05-20T15:08:09Z","sha256":"71ad42f4bfd953311c2d69f622cc6e8d5193a8852ac0bbc9ea0781ac6b651390","source":"amazon-inspector","versions":["3.0.21-cpp"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@nutui/nutui-react-taro/v/3.0.21-cpp"}],"affected":[{"package":{"name":"@nutui/nutui-react-taro","ecosystem":"npm","purl":"pkg:npm/%40nutui%2Fnutui-react-taro"},"versions":["3.0.21-cpp"],"database_specific":{"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"f64960d0651688802c2131d87caae781fe07c86a12084fcddfe8bb932897f8dd","tlsh":"cad05ba601ed23b0ad722c41fd5290f3658b4a225510fd72d14d416f9bc5416413b1fb"},{"path":"package.json","sha256":"c16e1f71f25c0e373c8e82e02cf14e238dc7992d40e645a483398d5c7e502bfc","tlsh":"97313f1d42608ff11e965afd6d1e2e53edfd168e605946ec42e292b0829c49cc0061fb"}],"package_integrity":[{"filename":"nutui-react-taro-3.0.21-cpp.tgz","hashes":{"sha512_sri":"sha512-xeoY5kI7v7AtwfaOrhcMNycAFqMLTkhL6p3D5QBjAeM0FIrWGUi7Q9uMlcQ8EAxZFMFE5XjoVo1Wii6zU7dGag==","sha1":"0daa53c4a4d61692890bfbd2b9da40e8bda60f93"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@nutui/nutui-react-taro/MAL-2026-4409.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}