{"id":"MAL-2026-4416","summary":"Malicious code in @ornexus/neocortex (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bb66a92e1a8c414ee0c8877998a9587b7c8a4be3b9b27b76d874329a87bec5dc)\nOn `npm install -g @ornexus/neocortex`, postinstall.js spawns install.sh (or install.ps1) which, by default, runs an `install_coderabbit` step that fetches `https://cli.coderabbit.ai/install.sh` and pipes it directly into `sh` (PowerShell equivalent on Windows). The fetch is unpinned (no version, no commit, no hash/signature verification), from a domain (`cli.coderabbit.ai`) unrelated to the package's stated publisher (ornexus / neocortex.sh), and unconditional — any compromise, DNS hijack, or content change at cli.coderabbit.ai yields arbitrary code execution on the installer's machine with the privileges of `npm install -g`. Additional aggressive lifecycle behavior compounds the concern: the same script silently `npm uninstall -g`s two other packages and removes a `neocortex-cli` binary from PATH, and it auto-registers MCP servers in the user's Claude Code config that will subsequently `npx -y \u003cpkg\u003e@latest` unpinned third-party packages on every Claude startup. The curl-pipe-sh from a non-publisher domain is the primary block basis; the other behaviors are unconsented mutations of installer state.\n","modified":"2026-05-27T00:31:58.076651166Z","published":"2026-05-21T20:05:46Z","withdrawn":"2026-05-26T21:41:23Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["4.55.4"],"id":"IN-MAL-2026-004010","import_time":"2026-05-26T05:51:45.894592558Z","modified_time":"2026-05-21T20:05:46Z","sha256":"1462eaef8fde587e799c63a72f1b25c20302c8b37931442a2fc948829404d321"},{"source":"amazon-inspector","versions":["4.55.4"],"id":"IN-MAL-2026-004009","import_time":"2026-05-26T05:51:45.775321022Z","modified_time":"2026-05-21T20:05:46Z","sha256":"bb66a92e1a8c414ee0c8877998a9587b7c8a4be3b9b27b76d874329a87bec5dc"},{"id":"IN-MAL-2026-004384","import_time":"2026-05-26T05:52:29.613968474Z","modified_time":"2026-05-23T22:12:01Z","sha256":"282b046894c2bc0b98fde7f613c5953a1260bdad57a3dd497d2abbf7b9a6c5d7","source":"amazon-inspector","versions":["4.55.5"]},{"source":"amazon-inspector","versions":["4.55.5"],"id":"IN-MAL-2026-004385","import_time":"2026-05-26T05:52:29.72387359Z","modified_time":"2026-05-23T22:12:02Z","sha256":"6c5d0c615cd8d559e82d028171e53a46b965176e61049fad203511d82a9015e8"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ornexus/neocortex/v/4.55.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@ornexus/neocortex/v/4.55.5"}],"affected":[{"package":{"name":"@ornexus/neocortex","ecosystem":"npm","purl":"pkg:npm/%40ornexus%2Fneocortex"},"versions":["4.55.4","4.55.5"],"database_specific":{"indicators":{"domains":["api.neocortex.sh"],"evidence_files":[{"tlsh":"9a739671e949d9f23649c26c69ca910533183217b90a7e09f95eb3083fdc35da2e637e","path":"install.sh","sha256":"68b7f11c381679ba8a9e53c7ceeb9102b63bc498ed846e14e80d892e9b426e3b"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-hz22PnN7e+xGtJUSLkpndADjPfAUKXaoXVlwnfTdQVGs1cE28rw2wROHG/1U4wXQGq1dJbkXuCNLSEcJPUEYjg==","sha1":"f6897b819cd25261b3478b3810b6037f2403535a"},"filename":"neocortex-4.55.4.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@ornexus/neocortex/MAL-2026-4416.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}