{"id":"MAL-2026-4687","summary":"Malicious code in tempo-modules (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6ad4276e2eafbe6d7040f94ac546ec20e7ac211e1e5906964c25f581a519d183)\ntempo-modules@99.0.1 is a dependency-confusion attack package. The package.json preinstall hook executes poc.js, which on every `npm install` harvests hostname, username, full network configuration (ipconfig/ip a/resolv.conf), git remote, parent package.json, and CI pipeline definitions (.gitlab-ci.yml,.github/workflows, Jenkinsfile, azure-pipelines.yml), plus whoami/id output. It then iterates process.env and selects any key containing TOKEN, AWS, AZURE, NPM, GITHUB, GITLAB, CI, JENKINS, BUILD, WALMART, etc. — bulk credential scraping of cloud and CI tokens. The collected JSON is POSTed to https://d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me/\u003cpkg\u003e (an Interactsh out-of-band collector), with a hex-encoded host-user identifier additionally DNS-exfiltrated. The package is published at version 99.0.1 with an internal-sounding name to win dependency-confusion resolution against an organization's private registry; the description self-identifies as a 'Dependency Confusion PoC' for a bug-bounty program, but the published artifact harms any installer that resolves this name. Multiple independent block signals stack: lifecycle preinstall outbound exfil, bulk credential harvest of CI/cloud tokens, and dependency-confusion version inflation.\n","modified":"2026-05-26T06:02:59.491240519Z","published":"2026-05-25T14:16:02Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-05-25T14:16:02Z","sha256":"6ad4276e2eafbe6d7040f94ac546ec20e7ac211e1e5906964c25f581a519d183","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-004688","import_time":"2026-05-26T05:53:05.48142811Z"},{"source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-004690","import_time":"2026-05-26T05:53:05.683197991Z","modified_time":"2026-05-25T14:16:03Z","sha256":"7fe7b908b9ebd546f11dc133ed56c3eb783c144f258be19e3e9e9a81770f09b2"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tempo-modules/v/99.0.1"}],"affected":[{"package":{"name":"tempo-modules","ecosystem":"npm","purl":"pkg:npm/tempo-modules"},"versions":["99.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tempo-modules/MAL-2026-4687.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"domains":["d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me","tempo-modules-7363616e2d66363038363261313036.d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me"],"evidence_files":[{"sha256":"9dd3b4f8639851060276bb073c73f2aa9f0f6e18fd192d7cc7033fb6750cf502","tlsh":"4071c7d482fa1e3022aa75b1f5cd000522d7d3933206f9d4798c1a919f9f8b482f67bd","path":"poc.js"},{"path":"package.json","sha256":"951454c50101c85b32a8d3c90d0aca1099807b6fa18229a23cee2885cff19dab","tlsh":"1ae07d78146010231ad8c3fa15b644479128dd0b51186c1d0757348c42aebb301bfb5d"}],"package_integrity":[{"filename":"tempo-modules-99.0.1.tgz","hashes":{"sha1":"e389b3127053cb950d1d97eeae078e787bcf2443","sha512_sri":"sha512-eDJHmsUH1H5hM2v8XDs+iqtb/XN8IHqARJd32htlVqQr+NjBlitkEGcFndZ9Lx9JkcuXsuwldKsEkAWw5ylU3Q=="}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}