{"id":"MAL-2026-4788","summary":"Malicious code in @godscene/web (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e1bd83a63f0426cc7c4e1a68886c36ff47de093d9b7edc6b410d16c928be50c1)\nPackage @godscene/web@1.7.22 is a re-bundled copy of the legitimate @midscene/web at the same version, preserving the original description, README, repository URL (web-infra-dev/midscene), homepage, class names, and exports. Only the scope was changed from @midscene to @godscene. The package.json rewrites the original dependencies @midscene/core, @midscene/shared, and @midscene/playground to @godscene/core@1.7.22, @godscene/shared@1.7.22, and @godscene/playground@1.7.22 — packages published under the attacker-controlled @godscene scope and outside this tarball. Installing or requiring this package transitively pulls and loads those attacker-controlled siblings, whose contents are not vetted by this wrapper. The wrapper itself contains no lifecycle hooks or overtly hostile code; the supply-chain attack edge is the dependency redirection into a hostile namespace, achieved by impersonating a legitimate package's identity.\n","modified":"2026-05-27T00:31:55.969585259Z","published":"2026-05-26T08:06:37Z","withdrawn":"2026-05-26T21:28:12Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.7.22"],"id":"IN-MAL-2026-004866","import_time":"2026-05-26T09:17:31.820785783Z","modified_time":"2026-05-26T08:06:37Z","sha256":"e1bd83a63f0426cc7c4e1a68886c36ff47de093d9b7edc6b410d16c928be50c1"},{"versions":["1.7.22"],"id":"IN-MAL-2026-004867","import_time":"2026-05-26T09:17:31.929537505Z","modified_time":"2026-05-26T08:06:38Z","sha256":"fe8a40a240d852a17faba624022dc9e2675f6041d3ac559b454c23fdd1f874ab","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@godscene/web/v/1.7.22"}],"affected":[{"package":{"name":"@godscene/web","ecosystem":"npm","purl":"pkg:npm/%40godscene%2Fweb"},"versions":["1.7.22"],"database_specific":{"indicators":{"evidence_files":[{"path":"package.json","sha256":"4cdd211f921ed03392de1ccbe5c5a66e9f0910915f21738eeb636e63d288f544","tlsh":"24c15419c4e91d6332d16ab2e66a2235b27281474b147f1473c9027c4f8c7ef12bf6ae"}],"package_integrity":[{"filename":"web-1.7.22.tgz","hashes":{"sha1":"d8379086809247b010235fd00339957c9a2181e8","sha512_sri":"sha512-g6PJmsAFaRRSxUY2+lkM4SqyiMbJ7UXCEpO7AZo92R234XXJtimjLbSSz7uadH5cvgmcCqaeAj+0b8d9rcibrg=="}}],"domains":["34.5.16.104.in-addr.arpa"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@godscene/web/MAL-2026-4788.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}