{"id":"MAL-2026-4559","summary":"Malicious code in fca-eryxenx (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (7569b032ce4e06251ebfe06b4fc124689f20ca0a7e14b5b2395dc7295bfa18c6)\nThe package's documented login API — login({email, password, twofactor}) — POSTs the caller's Facebook email, password, and 2FA secret to https://minhdong.site/api/v1/facebook/login_ios as the hardcoded default destination, rather than to Facebook directly. In module/loginHelper.js:62, baseUrl resolves to `apiBaseUrl || config.apiServer || \"https://minhdong.site\"`, so any caller who does not override apiServer relays full Facebook account credentials (including 2FA seed) to the author's domain. The author's server then returns cookies/access_token to the caller, giving the author full account-takeover material for every default-configuration use of the package. While the apiServer setting is documented as configurable, the silent-relay shape — caller-supplied secrets unconditionally flowing to the author's endpoint by default through the package's advertised API — meets the definition of silent-relay. A separate optional WebSocket remote-control channel exists but is off by default and uses a user-supplied URL, so it is not the basis of this verdict.\n","modified":"2026-08-05T22:19:51.369541942Z","published":"2026-05-20T01:04:09Z","withdrawn":"2026-05-26T22:13:04Z","database_specific":{"malicious-packages-origins":[{"versions":["6.0.0"],"id":"IN-MAL-2026-003338","import_time":"2026-05-26T05:50:27.131201465Z","modified_time":"2026-05-20T01:04:09Z","sha256":"7569b032ce4e06251ebfe06b4fc124689f20ca0a7e14b5b2395dc7295bfa18c6","source":"amazon-inspector"},{"id":"IN-MAL-2026-015818","import_time":"2026-08-05T16:13:49.479891582Z","modified_time":"2026-08-05T16:00:32Z","sha256":"4bad278bb4e64ab30b52705bf4a0a40645c5bd1bdc439ab303656097e60d30a1","source":"amazon-inspector","versions":["39.5.0"]},{"source":"amazon-inspector","versions":["39.9.0"],"id":"IN-MAL-2026-015896","import_time":"2026-08-05T21:31:21.5512379Z","modified_time":"2026-08-05T21:21:01Z","sha256":"edae5b03686d92b0458c18e199d7f46d8da0a30e9f2b8e33772f40e508d53c59"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fca-eryxenx/v/6.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fca-eryxenx/v/39.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fca-eryxenx/v/39.9.0"}],"affected":[{"package":{"name":"fca-eryxenx","ecosystem":"npm","purl":"pkg:npm/fca-eryxenx"},"versions":["6.0.0","39.5.0","39.9.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"fca-eryxenx-6.0.0.tgz","hashes":{"sha512_sri":"sha512-Pj8zrqTlzTh0IiF8u9hLLNymbK3BlnN0YShGr1gVBiWVHoRCA+XQRRxk2C4gEGUxYQUgcGoIuSB4aMO/rKqQkw==","sha1":"728a19cfbf372a0fb19b1c193ff14211cdd6ddf5"}}],"evidence_files":[{"path":"module/loginHelper.js","sha256":"6e9bfca3cdd8b97d3ce0cc6aba7799ff4dea0af41f4131a47c62504f5809c0cf","tlsh":"0633b71d71fb102505336078678ba011756aa0533688cde9bb9ca3346f8552acebfbdb"},{"tlsh":"6c51ab5e94f3612243b3202e4b9bc4267122d153231eee907b8d83a0df696ec92e37d5","path":"src/remote/remoteClient.js","sha256":"b3b67a5eead971c4575b2d910858955937cec7bc638c49383dda93726e9f6ccf"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/fca-eryxenx/MAL-2026-4559.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com","inspector-research@amazon.com"],"type":"FINDER"}]}