{"id":"MAL-2026-4434","summary":"Malicious code in @semacode/cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (28a3662b8e26593b7bfec35d4d4f02595144885ee738891c4c9e6a89f9e50fbb)\nThe bundled CLI (dist/index.js) contains a hardcoded outbound POST to https://sema.otimitare.online combined with reads of process.env and process.platform in the same module. The destination domain does not match any documented publisher infrastructure for a CLI tool and the call site issues an HTTP POST carrying environment- and platform-derived data. This pattern — hardcoded non-publisher C2 + env/platform reads + POST in a tool's main bundled entry — is the exfiltration shape and not consistent with normal telemetry from a reputable vendor (no opt-out, undocumented destination, suspicious lookalike-style hostname under a generic.online TLD).\n","modified":"2026-05-27T00:31:58.063825954Z","published":"2026-05-20T08:31:36Z","withdrawn":"2026-05-26T18:24:46Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-05-26T05:50:44.704163199Z","modified_time":"2026-05-20T08:31:36Z","sha256":"28a3662b8e26593b7bfec35d4d4f02595144885ee738891c4c9e6a89f9e50fbb","source":"amazon-inspector","versions":["1.5.28"],"id":"IN-MAL-2026-003501"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@semacode/cli/v/1.5.28"}],"affected":[{"package":{"name":"@semacode/cli","ecosystem":"npm","purl":"pkg:npm/%40semacode%2Fcli"},"versions":["1.5.28"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"c65ca3fbab007b8e6861743a487d64ba6e322544a5e7474dc3089f8a2f832fac","tlsh":"fb54d75a59f705121e7722a86a8b4013b9385e432d0ced4abb5d83d01fcd96d92f3bec"}],"package_integrity":[{"filename":"cli-1.5.28.tgz","hashes":{"sha1":"7ddbe9b44e014ac9cdaf01b67b64a5059eae0e6a","sha512_sri":"sha512-Afdnku795+xMei6kdxLNH1aVX5XSKzngLHjzKVbjJc3k6u/GZSzNGdZOJJSd6gS2KdCjzhgaTda7mPm2wAz9IQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@semacode/cli/MAL-2026-4434.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}