{"id":"MAL-2026-4551","summary":"Malicious code in encrata-cli (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e98813f52fa8e9fc3c04bffd023445dbfed4a9b405d1e3f85511673f5e86dce7)\npackage.json declares `\"postinstall\": \"node install.js\"`, which runs at install time. install.js requires both `child_process` and `https`, branches on `process.platform` to enumerate host details, and issues an outbound `https.get(...)` carrying the collected data. This is the canonical install-time system-information exfiltration shape: child_process to spawn host-info commands, platform-gated logic to pick the right binary per OS, and HTTPS egress to ship the result. There is no legitimate reason for a CLI's postinstall to gather host metadata and POST/GET it off-host. Installing this package on any machine (developer laptop, CI runner, build server) discloses host details to a remote endpoint and provides an install-time code-execution surface.\n","modified":"2026-05-26T06:02:29.703269727Z","published":"2026-05-20T12:36:31Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-05-26T05:52:01.666435355Z","modified_time":"2026-05-22T06:16:26Z","sha256":"80b70f02e409ec9eb28e4ddcdf37d477f4ffe774ff0a4026f0e242dcc0a1ef48","source":"amazon-inspector","versions":["0.2.0"],"id":"IN-MAL-2026-004147"},{"versions":["0.2.0"],"id":"IN-MAL-2026-004146","import_time":"2026-05-26T05:52:01.559120786Z","modified_time":"2026-05-22T06:16:26Z","sha256":"8a7070dd3d284cb91d046f6be633445a29af8e30a4fc0d3c77dce18bf847c0b0","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-003529","import_time":"2026-05-26T05:50:48.039101961Z","modified_time":"2026-05-20T12:36:32Z","sha256":"b4eea8e53244b7114760ece8c8842f1936baca2e93ba8f49c76f7d02e7f0ffb6"},{"sha256":"e98813f52fa8e9fc3c04bffd023445dbfed4a9b405d1e3f85511673f5e86dce7","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-003528","import_time":"2026-05-26T05:50:47.903193915Z","modified_time":"2026-05-20T12:36:31Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/encrata-cli/v/0.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/encrata-cli/v/0.1.0"}],"affected":[{"package":{"name":"encrata-cli","ecosystem":"npm","purl":"pkg:npm/encrata-cli"},"versions":["0.2.0","0.1.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/encrata-cli/MAL-2026-4551.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"c86aeb8a58c9f21a7e7a27d663f9edb009d7bffaa482c8034d0e91bc23adb8f5","tlsh":"8551950d97e252305eb052e7b98b1c17e49b02237706cd88f2ac46183ff6d6495a63eb","path":"install.js"},{"path":"package.json","sha256":"3050a2eaa30e1acece5878910cbd1e84b6ab2a389afee13a3ea36e411985941e","tlsh":"5e0199288e3109133bd895a81d99240a7523190b0cc47c263baf003d17ce23a207e2fe"}],"package_integrity":[{"hashes":{"sha1":"90d211a7c3dc95b23f4a17bd7753e6331bf4cf90","sha512_sri":"sha512-gQwz1rVjTnIh7tySZb1kMHDuCyxsVZyH2I7DSMXDw596Ko7YNtm0r1e8U7RiSXiI7c6geggXwgorVzDhzxDYFw=="},"filename":"encrata-cli-0.2.0.tgz"}],"domains":["github.com"]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}