{"id":"MAL-2026-4691","summary":"Malicious code in testnpmnmp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e82942b1fcdaed1a1085ad9590ef93704e276c5c5ca1622884abac014f03980f)\npackage.json declares `\"preinstall\": \"./scripts/postbuild\"`, where `scripts/postbuild` is a 976,568-byte unsigned, unhashed, unversioned Linux ELF executable shipped in the tarball. The package's only JavaScript source (src/index.js) is a trivial stub that exports `() =\u003e { console.log(\"hello\") }`, with the bundled output (dist/index.cjs.js) matching. Nothing in the package's stated Arweave/Warp-contracts wrapper purpose justifies a native executable, and the binary's embedded strings (`LIBBPF_0.0`, `PTRACE`, `NETLINK`, `HTTP/1.1`, `USERPROFILE`, `RSA_PKCS1_`, `Ed25519`) indicate credential-handling and network-agent capabilities rather than build tooling. On `npm install`, the binary runs with the installer's privileges before any user inspection; the JS stub is a cover for shipping and executing arbitrary native code. The package name `testnpmnmp` and stub source further indicate a throwaway dropper rather than a real library.\n\n## Source: google-open-source-security (146faaf0d97c6a533a969bc3f3f117811f9317dc865ed4ab37f1679842ddeaae)\nThis package was compromised as part of the IronWorm campaign. This campaign executes a malicious binary payload during installation via a preinstall hook. The payload is a Rust-built infostealer that targets developer environments, scanning for and harvesting credentials related to cloud providers, object storage, databases, source-control, package registries, and AI developer tools. It also targets cryptocurrency wallets, specifically injecting a malicious JavaScript hook into the Exodus desktop wallet to capture passwords and recovery phrases. Furthermore, the malware exhibits worm-like behavior by stealing GitHub and NPM credentials to push malicious updates to the victim's repositories and publish trojanized packages, and it uses an eBPF-based kernel rootkit to hide its processes and network connections on Linux systems.\n","modified":"2026-06-04T23:16:45.859958978Z","published":"2026-05-26T01:00:12Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-05-26T05:53:19.958201736Z","id":"IN-MAL-2026-004813","modified_time":"2026-05-26T01:00:12Z","versions":["1.0.21"],"source":"amazon-inspector","sha256":"e82942b1fcdaed1a1085ad9590ef93704e276c5c5ca1622884abac014f03980f"},{"versions":["1.0.21"],"source":"google-open-source-security","sha256":"146faaf0d97c6a533a969bc3f3f117811f9317dc865ed4ab37f1679842ddeaae","import_time":"2026-06-04T22:42:01.227855Z","modified_time":"2026-06-04T22:28:51.769005667Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/testnpmnmp/v/1.0.21"},{"type":"ARTICLE","url":"http://www.ox.security/blog/ironworm-supply-chain-malware-hits-npm/"},{"type":"ARTICLE","url":"https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/"}],"affected":[{"package":{"name":"testnpmnmp","ecosystem":"npm","purl":"pkg:npm/testnpmnmp"},"versions":["1.0.21"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/testnpmnmp/MAL-2026-4691.json","indicators":{"evidence_files":[{"tlsh":"d1f02830cd62da6309d960f11478a387aab59c67448cfc0833c6624d0b5e29b11fe9ac","path":"package.json","sha256":"917cfda6f5d0bc7629dd175ba359d9ce80c4f13b882e9cc8ef8b1458fb021828"},{"tlsh":"07f055413bed7172708d20d08a32493a3a23cdb93f487894a2dc72e725d79e883a34f0","path":"src/index.js","sha256":"f7cfb8d233e55624838f80566e10ca192c46426a2e84d3adb6eb244dbc784139"}],"package_integrity":[{"filename":"testnpmnmp-1.0.21.tgz","hashes":{"sha512_sri":"sha512-bbkVKearaasNCBSqD+OjMx2JNoCzhNWGRfrlrNlhaCy13r4SCNQHMYV1zkovyVeHEmEzlXKpLUvqOuTrXpvWYA==","sha1":"e5fa91f4b94513e1bda934d32567270e8d27d97e"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}