{"id":"MAL-2026-5570","summary":"Malicious code in nim-submit-for-test (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2bf75301042574897cc2f4bd8f3b8939fe4ac7a958f2cfe2404bbbee149797d0)\nOn npm install, the package's postinstall hook executes lib/_compiler.js, which spawns a detached Node process that collects host identity (hostname, username, cwd, IP addresses, npm registry) and the names of environment variables matching NPM|NODE|CI|JENKINS|GIT|BUILD|RUNNER|DOCKER|KUBE|REGISTRY, then POSTs them via https.request to a hardcoded DingTalk webhook (oapi.dingtalk.com/robot/send) with an embedded access token. Before sending, the script checks the installer's username and hostname against an evasion list ('sandbox','malware','analyst','cuckoo','analysis','sample') and exits silently when matched, to avoid running in security analysis environments. The combination of automatic install-time execution, host/CI metadata collection, hardcoded attacker-controlled webhook, and analyst-environment evasion is a clear supply-chain exfiltration beacon.\n","modified":"2026-06-11T05:46:31.492558589Z","published":"2026-06-11T04:46:02Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["2.2.0"],"id":"IN-MAL-2026-005471","import_time":"2026-06-11T05:40:58.188983343Z","modified_time":"2026-06-11T04:46:02Z","sha256":"2bf75301042574897cc2f4bd8f3b8939fe4ac7a958f2cfe2404bbbee149797d0"},{"sha256":"77bfef43e57cee7068599b0d1af2fd6b5400e7298aa9833fdffda514a28eeeb2","source":"amazon-inspector","versions":["2.2.0"],"id":"IN-MAL-2026-005472","import_time":"2026-06-11T05:40:58.261937784Z","modified_time":"2026-06-11T04:46:03Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/nim-submit-for-test/v/2.2.0"}],"affected":[{"package":{"name":"nim-submit-for-test","ecosystem":"npm","purl":"pkg:npm/nim-submit-for-test"},"versions":["2.2.0"],"database_specific":{"indicators":{"domains":["oapi.dingtalk.com"],"evidence_files":[{"path":"lib/_compiler.js","sha256":"bd158e2c3e12c1c3661649a5215fafec97c606984dd005a76cc43df7c120d80d","tlsh":"d741b5e674a97638177c85c290821016da57e2223583f8e0fc2c41d61bc7cfa9af197e"}],"package_integrity":[{"filename":"nim-submit-for-test-2.2.0.tgz","hashes":{"sha512_sri":"sha512-YJEPRf1iGYTnLiuGLOghEE4tUovXmi9ygxEr+ZsT3bwJELWergDWHrr0x6lWczjuY9/eT4OE+uuAJ8RXcHdRtA==","sha1":"6cefc3a4fe0e36e4eb878b1ef208dff76fd6dbe9"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nim-submit-for-test/MAL-2026-5570.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}