{"id":"MAL-2026-5439","summary":"Malicious code in exodus-checkout-signer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (921c5ef246587db452bdb65aae12321f4de868e7882f9550f9b9e32300ae792c)\nexodus-checkout-signer is the unscoped name of the scoped package @exodus/checkout-signer and self-describes (in README and package.json) as a dependency-confusion proof-of-concept targeting installers who follow Exodus's documented install command and drop the scope. The package's main entry throws on require so any caller fails loudly, but on `npm install` the `postinstall` script unconditionally runs `node src/canary.js`, which performs a DNS lookup and an HTTPS GET to `96e03fa6c292469a-172-245-86-254.serveousercontent.com` — a Serveo SSH-tunneling endpoint with a raw IP (172.245.86.254) embedded in the subdomain — passing the package name and version as query parameters (`/canary-install?pkg=...&ver=...`). No installer secrets are exfiltrated, but every installation reveals the victim's source IP, timing, and corporate-network egress to an anonymous third-party tunnel operator that is not affiliated with the impersonated Exodus publisher. The combined name-confusion against a top-shelf wallet vendor's documented scope plus install-time beaconing to attacker-controllable infrastructure is a live supply-chain attack regardless of the author's stated 'research' intent.\n","modified":"2026-06-09T18:01:34.360510038Z","published":"2026-06-09T17:44:56Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-06-09T17:44:56Z","sha256":"7da50adb6560d5d1153657f16884e3acba9fd19865b0c1f6a90da176ae951f98","source":"amazon-inspector","versions":["99.0.0-canary.1"],"id":"IN-MAL-2026-005120","import_time":"2026-06-09T17:45:55.510506284Z"},{"source":"amazon-inspector","versions":["99.0.0-canary.1"],"id":"IN-MAL-2026-005119","import_time":"2026-06-09T17:45:55.481753954Z","modified_time":"2026-06-09T17:44:56Z","sha256":"921c5ef246587db452bdb65aae12321f4de868e7882f9550f9b9e32300ae792c"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exodus-checkout-signer/v/99.0.0-canary.1"}],"affected":[{"package":{"name":"exodus-checkout-signer","ecosystem":"npm","purl":"pkg:npm/exodus-checkout-signer"},"versions":["99.0.0-canary.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"exodus-checkout-signer-99.0.0-canary.1.tgz","hashes":{"sha1":"42552c78e8273a14286946f7f5624a35bdcfa4d8","sha512_sri":"sha512-ReYMnn9NmvSTSQTL1b7j9Hw+JGEIHLdN5OGNQHU98eqP1yy3Nan0wUUBemMRvbg9JwPMneCyOJHyX1ZgvuUqIg=="}}],"domains":["install.96e03fa6c292469a-172-245-86-254.serveousercontent.com","96e03fa6c292469a-172-245-86-254.serveousercontent.com"],"evidence_files":[{"sha256":"55b7cf64d389123cf33b2cdac609da9a3c5bce4c3eb49270b469e23775f34359","tlsh":"be1114686181033207b629fa61db27e297e9f17133148daa75cd761e230696b831b30f","path":"README.md"},{"tlsh":"a311e1b75ce053364ff113ca91a3609f671794a070949ae185de269402c2ff1d3775ea","path":"src/canary.js","sha256":"0aa6957cb8e429fa03f5f552770bd74abf3e5de7528912f7b750c78fd2bd98ab"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exodus-checkout-signer/MAL-2026-5439.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}