{"id":"MAL-2026-4494","summary":"Malicious code in axois-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (48eb1a16cb7cac016f30a49f81d472b9b4e02236b97c5daaea4446b74e6aa069)\nThe package name is a single-character transposition of `axios`. `package.json` declares `preinstall`, `install`, and `postinstall` hooks all pointing at `postinstall.js`, guaranteeing execution on `npm install`. `postinstall.js` reads `~/.ssh/id_*`, `~/.aws/credentials`, `~/.aws/config`, `~/.config/gcloud/application_default_credentials.json`, `~/.azure/accessTokens.json`, `~/.npmrc`, shell histories, browser profile data, crypto wallet files, the entire `process.env`, and recursively walks `~/projects`, `~/dev`, `~/code`, `~/workspace`, and the current working directory for `.env` files. Collected data is POSTed via plain HTTP to `http://80.200.28.28:2222/collect` (hardcoded as `C2_HOST` at line 11). Author comments in the source explicitly label installers as 'victims' (`// Change this to your PUBLIC IP when deploying to victims`) and construct a `VICTIM_ID`, leaving no benign interpretation. The exposed `fetchData` API in `index.js` is a stub that only `console.log`s — the package has no legitimate function.\n","aliases":["GHSA-pvvv-cmc6-c323"],"modified":"2026-09-01T11:31:05.848728827Z","published":"2026-05-20T01:33:43Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.9"],"id":"IN-MAL-2026-003365","import_time":"2026-05-26T05:50:30.038124505Z","modified_time":"2026-05-20T01:33:43Z","sha256":"2c958ad366d3cf211d3687734b5515662d21eb63135675984966149e7205f5ee","source":"amazon-inspector"},{"modified_time":"2026-05-20T01:33:43Z","sha256":"348b9dab1b41fbf96d8b2eb2d57a630c5173a7a59b446495ae44f2c8c270fc54","source":"amazon-inspector","versions":["1.0.9"],"id":"IN-MAL-2026-003366","import_time":"2026-05-26T05:50:30.129341041Z"},{"source":"amazon-inspector","versions":["1.0.8"],"id":"IN-MAL-2026-003383","import_time":"2026-05-26T05:50:32.292390413Z","modified_time":"2026-05-20T01:48:45Z","sha256":"3bde7de4bfb2aa11618fdd40c2fa9148ea6528d5e0e198bf2a7148d013021d6b"},{"sha256":"48eb1a16cb7cac016f30a49f81d472b9b4e02236b97c5daaea4446b74e6aa069","source":"amazon-inspector","versions":["1.0.5"],"id":"IN-MAL-2026-003384","import_time":"2026-05-26T05:50:32.381114054Z","modified_time":"2026-05-20T01:56:23Z"},{"import_time":"2026-05-26T05:50:30.947293738Z","modified_time":"2026-05-20T01:42:02Z","sha256":"6c7f0094b893662a5bccb61ccbb5acdc9cef0e7d29361133c47456ace1d46836","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-003373"},{"sha256":"96352f83bd4eb19f3b558b436dbcb497759f2f44c09ba6e9f0c283a2bdf4b61a","source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-003370","import_time":"2026-05-26T05:50:30.567604347Z","modified_time":"2026-05-20T01:40:54Z"},{"versions":["1.0.8"],"id":"IN-MAL-2026-003382","import_time":"2026-05-26T05:50:32.196030532Z","modified_time":"2026-05-20T01:48:45Z","sha256":"a0138ed11110dbbde8b54451da2c6a188d1ce1b885f57b4502b0e3d15af797cc","source":"amazon-inspector"},{"import_time":"2026-05-26T05:50:30.473042333Z","modified_time":"2026-05-20T01:40:53Z","sha256":"ebd0e0c4d55ecc3d8d7d292bfbf40484d853466a4b12cbd7a4da5171cac12e74","source":"amazon-inspector","versions":["1.0.7"],"id":"IN-MAL-2026-003369"},{"import_time":"2026-05-26T05:50:31.871438811Z","modified_time":"2026-05-20T01:44:45Z","sha256":"ef6753fc762c223001f634d4abd6f0fd9e578ec3b042931a2b4ea0cdaab1ef26","source":"amazon-inspector","versions":["1.0.4"],"id":"IN-MAL-2026-003379"},{"modified_time":"2026-07-07T12:40:36Z","sha256":"27bd573042acab3a2f8d6f9bdc710d06c48c53ae728f32db90621ffe6f81c4e8","source":"reversing-labs","versions":["1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9"],"id":"RLMA-2026-04953","import_time":"2026-07-09T09:16:18.70394551Z"},{"source":"reversing-labs","id":"RLUA-2026-06078","import_time":"2026-09-01T11:17:56.877764463Z","modified_time":"2026-08-24T16:40:44Z","sha256":"6350a5cf6957e04ea75045122049f8e3d499c34bd5be352194cef68b8a27db82"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/axois-utils/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axois-utils/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axois-utils/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axois-utils/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axois-utils/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/axois-utils/v/1.0.4"},{"type":"WEB","url":"https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pvvv-cmc6-c323"}],"affected":[{"package":{"name":"axois-utils","ecosystem":"npm","purl":"pkg:npm/axois-utils"},"versions":["1.0.9","1.0.8","1.0.5","1.0.6","1.0.7","1.0.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"domains":["api.ipify.org","b94b6bcfa27554.lhr.life"],"evidence_files":[{"path":"distrube.js","sha256":"308b15c023088a7188dea4ef609010ac2493eb4c365b103053d7621a9ca5b935","tlsh":"6b3293e066f79160127395aa832ba5061177f0033902edb8ff9dd3451f8a52c87f26ed"}],"package_integrity":[{"filename":"axois-utils-1.0.9.tgz","hashes":{"sha512_sri":"sha512-EX4QmTBU8U1aSejnWVtJiF+EisFnm+0NH5YqaJLddrK91ttXJ01lTiYi+ihetV6wxeI9HFLnuCEQ8KThl+DiQg==","sha1":"1e3108220b931a6a8005b6f19cd729856847fc64"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axois-utils/MAL-2026-4494.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}