{"id":"MAL-2026-4423","summary":"Malicious code in @refactco/refact-os (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (072881a1fd9241acfcd601ad5387b0338a26ff4828763658c3840b43a3cedb1c)\nRunning this package's `refact-os init` CLI scaffolds AI-editor hook configurations (`.claude/settings.json`, `.cursor/hooks.json`) and copies two Python hooks (`templates/base/agent/hooks/claude-sync-transcript.py`, `templates/base/agent/hooks/send-transcript-to-remote-server.py`) into the user's project. The Cursor hooks register on `beforeSubmitPrompt` and `afterAgentResponse`, and the Claude hook fires on `SessionEnd`. After scaffolding, every user prompt, every assistant response, and the full per-session JSONL transcript — together with git remote URL and OS hostname/user — are POSTed to `https://159.223.97.72:8443/transcript`, a hardcoded public DigitalOcean IPv4 address. TLS certificate verification is explicitly disabled (`ctx.check_hostname = False; ctx.verify_mode = ssl.CERT_NONE`). Source comments describe the destination as a 'self-signed cert on loopback' / 'loopback / controlled endpoints only', but 159.223.97.72 is not a loopback address — it is publicly routable. The README advertises the package as an 'agent-first repo standard' / folder-layout scaffolder and does not disclose any transcript upload. Once installed and used as documented, every AI chat session — including source code, secrets pasted in prompts, and internal documentation — is silently forwarded to an author-controlled remote IP without consent and without TLS validation.\n","modified":"2026-05-27T00:32:02.680400284Z","published":"2026-05-25T04:23:38Z","withdrawn":"2026-05-26T21:41:23Z","database_specific":{"malicious-packages-origins":[{"versions":["1.5.0"],"source":"amazon-inspector","sha256":"072881a1fd9241acfcd601ad5387b0338a26ff4828763658c3840b43a3cedb1c","import_time":"2026-05-26T05:52:52.807725319Z","id":"IN-MAL-2026-004580","modified_time":"2026-05-25T04:23:38Z"},{"import_time":"2026-05-26T05:52:52.902668047Z","id":"IN-MAL-2026-004581","modified_time":"2026-05-25T04:59:21Z","versions":["1.5.2"],"source":"amazon-inspector","sha256":"4ac0cf32ff1147655976338fa4e99b9b56b412fd5a0299b932c7f84d95150379"},{"sha256":"c80a2076f29e220293219b51216f61f71274d4b49cdcb8590d05e4071e1722e2","import_time":"2026-05-26T09:17:32.287920813Z","id":"IN-MAL-2026-004871","modified_time":"2026-05-26T08:28:00Z","versions":["1.6.0"],"source":"amazon-inspector"},{"modified_time":"2026-05-26T14:48:26Z","versions":["1.6.1"],"source":"amazon-inspector","sha256":"55c92841bffd38db4a5ebc67cf4ce3c7f580446074ed5e93864d837e5b7f24d0","import_time":"2026-05-26T15:07:43.410756138Z","id":"IN-MAL-2026-004923"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@refactco/refact-os/v/1.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@refactco/refact-os/v/1.5.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@refactco/refact-os/v/1.6.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@refactco/refact-os/v/1.6.1"}],"affected":[{"package":{"name":"@refactco/refact-os","ecosystem":"npm","purl":"pkg:npm/%40refactco%2Frefact-os"},"versions":["1.5.0","1.5.2","1.6.0","1.6.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-NpmgUfqXU276qGBwO9KLRKzEiVa8SqH7D8XXrVegulOmSnJqo4rS/1MeTffi5LWNht6WKIFC7dAUGzWtf789ig==","sha1":"f5b6527dabefc8fb7705602208c2dac9ed8b20fc"},"filename":"refact-os-1.5.0.tgz"}],"evidence_files":[{"path":"templates/base/agent/hooks/claude-sync-transcript.py","sha256":"f122221d733fa206df07da3f4e314919138847406760ecfaf02de209e79e45f9","tlsh":"57029425bd1e9433c3e3c22880b9c4552739e9073705a834baddc6991f8daf9c5b46de"},{"path":"templates/base/agent/hooks.json","sha256":"f982098e8f2eaeb328707b95d8daa23c3d50d77f9dc7f143d0b0f168a718a78d","tlsh":"a501a4aee8e9085318d1353847fd54405aecf44b1b99bc02779f481d4f19a9e6ea00fb"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@refactco/refact-os/MAL-2026-4423.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}