{"id":"MAL-2026-4462","summary":"Malicious code in @vino.tian/vibe-kanban (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7f1533bb7e55b1bcd10291aa9f19e2a5cbe5755a7a6a7343d38fbd3ff8064a1f)\nThis package is published as `@vino.tian/vibe-kanban` and copies its README, name, and feature description from BloopAI's legitimate `vibe-kanban` project, but its binary distribution channel is a different, unrelated GitHub account. When the installed CLI is invoked (`npx @vino.tian/vibe-kanban`), `bin/cli.js` constructs a release-asset URL of the form `https://github.com/tianweilong/deploy-center/releases/download/\u003ctag\u003e/\u003cplatform\u003e.{zip,tar.gz}`, downloads the archive, extracts it, and runs the resulting binary via `execSync(\"${bin}\", { stdio: 'inherit' })`. A SHA-256 check is performed against a checksums file, but the checksums file is fetched from the same `tianweilong/deploy-center` repo as the archive, so the verification provides no protection — whoever controls that repo controls both the bytes and the expected hash. Additional integrity concerns: `package.json` declares `\"main\": \"index.js\"` but no `index.js` is shipped, and an unsubstituted `__R2_PUBLIC_URL__` placeholder remains in the desktop-installer path. Net effect: a user who installs and runs this package executes arbitrary bytes served by an attacker-controlled GitHub account under the guise of a known OSS tool.\n","modified":"2026-05-27T00:32:05.718324713Z","published":"2026-05-21T14:20:57Z","withdrawn":"2026-05-26T21:14:22Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["0.1.4420"],"id":"IN-MAL-2026-004665","import_time":"2026-05-26T05:53:02.921127792Z","modified_time":"2026-05-25T14:03:09Z","sha256":"6714cac258173856d447c9fe51c19f5b96a59c3c5c3d0bb64167da5792c281fa"},{"id":"IN-MAL-2026-003867","import_time":"2026-05-26T05:51:28.818950425Z","modified_time":"2026-05-21T14:20:57Z","sha256":"7f1533bb7e55b1bcd10291aa9f19e2a5cbe5755a7a6a7343d38fbd3ff8064a1f","source":"amazon-inspector","versions":["0.1.4413"]},{"import_time":"2026-05-26T05:52:44.081621756Z","modified_time":"2026-05-24T12:54:43Z","sha256":"99c6b49d225e4520c1357625e723ccb4c5e1c8a70abbfd8498d1e07f32c4b624","source":"amazon-inspector","versions":["0.1.4418"],"id":"IN-MAL-2026-004506"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@vino.tian/vibe-kanban/v/0.1.4420"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@vino.tian/vibe-kanban/v/0.1.4413"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@vino.tian/vibe-kanban/v/0.1.4418"}],"affected":[{"package":{"name":"@vino.tian/vibe-kanban","ecosystem":"npm","purl":"pkg:npm/%40vino.tian%2Fvibe-kanban"},"versions":["0.1.4420","0.1.4413","0.1.4418"],"database_specific":{"indicators":{"package_integrity":[{"filename":"vibe-kanban-0.1.4420.tgz","hashes":{"sha512_sri":"sha512-yVIhzLN6T3dXGjCFhKffohfrMjEJHsls4dZ0b4YUOXT/B4T3zFt66SRITxST/Pu9vrti5ZKu24rSP2rbDZiqow==","sha1":"90d8b8d5c7ac6fdce3bd3437793979a343522fb8"}}],"evidence_files":[{"path":"bin/cli.js","sha256":"2c441691c83cfcc711e0b1de4db774fbf60618e270b5f2cc2717be7bf302b988","tlsh":"7333d9092af7512202b3607a5e8f24157675c7172609ed5cfaece7e02f95138c6f3ba8"},{"sha256":"05082787388040207f136a3a68867bd3196535723474713af3d62b9c79665c8c","tlsh":"82117620cab8a8b301dd55faec790283e5725a278968fd1c73c2411c0b6e17a10beb6c","path":"package.json"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@vino.tian/vibe-kanban/MAL-2026-4462.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}