{"id":"MAL-2026-4493","summary":"Malicious code in axiosqqq (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a9cf5bc7a896b21f9af923c60b9283758bf46d4fb279f752a42bae43bb6006aa)\nPackage name `axiosqqq` is a 3-character-suffix typosquat of `axios` and ships axios's verbatim source, README, and CHANGELOG to impersonate the legitimate package. The only material divergence from upstream axios is an added runtime dependency in package.json: `\"@caspianph/storyteller\": \"^1.0.0\"`. No file in the tarball imports or references this dependency, so it serves no functional purpose in the package; its only effect is that `npm install axiosqqq` resolves and installs `@caspianph/storyteller`, whose lifecycle hooks and main module will execute in the installer's environment. This is the namespace-abuse / smuggled-transitive-dependency pattern: the lure package mimics a top-tier registry name to get installed, and the actual payload is the unrelated scoped package pulled in transitively. The static C2/POST/ping pattern matches fire on the bundled axios.cjs and reflect axios's normal HTTP-client surface (POST, fetch, ping helpers) rather than added exfiltration code — the typosquat's harm is structural, via the injected dependency, not via modifications to the axios bundle itself.\n","modified":"2026-06-18T17:16:45.926419466Z","published":"2026-05-20T04:16:47Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-003459","modified_time":"2026-05-20T04:16:47Z","versions":["1.16.2"],"source":"amazon-inspector","sha256":"a9cf5bc7a896b21f9af923c60b9283758bf46d4fb279f752a42bae43bb6006aa","import_time":"2026-05-26T05:50:40.973991855Z"},{"id":"IN-MAL-2026-006683","modified_time":"2026-06-15T19:48:47Z","versions":["1.16.3"],"source":"amazon-inspector","sha256":"2b58b49bb1c51a7712d6502cddc9851877cacc0e3e24d3964e6982a4f7b9a1ce","import_time":"2026-06-15T20:14:27.42946768Z"},{"sha256":"a86e56aa792475722bbbe348d71549c7634f98d15c4565e3831d58a0550181c5","import_time":"2026-06-18T17:08:46.109260691Z","id":"IN-MAL-2026-006984","modified_time":"2026-06-18T16:09:23Z","versions":["1.16.9"],"source":"amazon-inspector"},{"versions":["1.16.13"],"source":"amazon-inspector","sha256":"da6aa9f34eaa3296ac59531a3a14a516dd055c8f239a1ebe6da8bb1c8a3c0277","import_time":"2026-06-18T17:08:46.182692252Z","id":"IN-MAL-2026-006985","modified_time":"2026-06-18T16:09:25Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/axiosqqq/v/1.16.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axiosqqq/v/1.16.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axiosqqq/v/1.16.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axiosqqq/v/1.16.13"}],"affected":[{"package":{"name":"axiosqqq","ecosystem":"npm","purl":"pkg:npm/axiosqqq"},"versions":["1.16.2","1.16.3","1.16.9","1.16.13"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"5e110fd6fa3afa14bf2671d756baa9f2972d3e27","sha512_sri":"sha512-an9BYensuEdOipJmFz/W9w2FhS4/ANZMs41uj+kRxzITC666Rdso+kVygGVCeYS3CgEeoFl3JqHODyTqDNl0xw=="},"filename":"axiosqqq-1.16.2.tgz"}],"evidence_files":[{"path":"package.json","sha256":"8f15d9ae65c6ea4dd4fec2b96c68d01cc60fa25c5d0d895f6253caa2002aa476","tlsh":"07d1ed62c89a4d572fe43aa8a85a9155b235c04fcc41f91d73ae424c4f4c72f32fb66e"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axiosqqq/MAL-2026-4493.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com","inspector-research@amazon.com"],"type":"FINDER"}]}