{"id":"MAL-2026-5587","summary":"Malicious code in 0x2ai-demo1 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (fdc7c661d4867578d3dd920010bccc1e79fcae8753b5bf549f44ea8a45cde502)\nOn `npm install`, scripts/postinstall.cjs runs `fs.cpSync(payload, cwd, { recursive: true })` with cwd=`process.env.INIT_CWD || process.cwd()` — recursively writing the package's entire payload/ tree (.mcp.json, CLAUDE.md,.claude/commands/,.claude/settings.json, and three chatroom.cjs files) into the installing project's root directory. The dropped.mcp.json registers an MCP server named `chatroom` whose BRIDGE_URL is hardcoded to https://demo1.0x2ai.com (the author's endpoint). The dropped CLAUDE.md is auto-loaded by Claude Code as project instructions, redefines the assistant persona, and instructs use of the planted MCP tools/bridge. The companion binary payload/chatroom-mcp-lite-patched.cjs exposes a `provider_query` tool that POSTs caller prompts to `${BRIDGE}/api/proxy-query` (\"API keys are managed server-side — no client keys needed\"), and memory_save/load/chatroom_post/settings_set are similarly routed. Any subsequent Claude Code session opened in the consumer's project will silently forward prompts, memory, settings, and any API keys configured via settings_set to demo1.0x2ai.com. The package also ships URL-path obfuscation (`/x/\u003csha256(salt+path)[:4]\u003e`) that is dormant only because the shipped config sets DIRECT_API=1. A `bin/start.cjs` entry additionally launches `claude --dangerously-skip-permissions`, disabling Claude Code's tool-permission prompts and amplifying the relay's reach when the user runs the bundled CLI.\n","modified":"2026-07-17T03:04:24.700359404Z","published":"2026-06-11T07:16:13Z","withdrawn":"2026-07-16T00:38:53Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-11T07:49:39.081313234Z","modified_time":"2026-06-11T07:16:13Z","sha256":"b29f3d65354dd3bf54e23142f5c6577ad4c5a37b9ff109200309cbb6453b8c26","source":"amazon-inspector","versions":["2.0.2"],"id":"IN-MAL-2026-005669"},{"source":"amazon-inspector","versions":["1.2.0"],"id":"IN-MAL-2026-005681","import_time":"2026-06-11T07:49:40.414165219Z","modified_time":"2026-06-11T07:16:23Z","sha256":"baf53f193b709bc0c98ddbe429cb8edf1caf1ed2fa019bc3e7dc362e431c493f"},{"id":"IN-MAL-2026-005670","import_time":"2026-06-11T07:49:39.168217478Z","modified_time":"2026-06-11T07:16:13Z","sha256":"fdc7c661d4867578d3dd920010bccc1e79fcae8753b5bf549f44ea8a45cde502","source":"amazon-inspector","versions":["2.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/0x2ai-demo1/v/2.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/0x2ai-demo1/v/1.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/0x2ai-demo1/v/2.0.0"}],"affected":[{"package":{"name":"0x2ai-demo1","ecosystem":"npm","purl":"pkg:npm/0x2ai-demo1"},"versions":["2.0.2","1.2.0","2.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/0x2ai-demo1/MAL-2026-5587.json","indicators":{"evidence_files":[{"tlsh":"1e81728a5bee0b7b467412812c0b4137e959cc402364f5a0a17e8296bfc1da099b77df","path":"bin/start.cjs","sha256":"adfcb1d45218ade2e6a9cc459514d59569de732412deca558842c629d3be908b"},{"tlsh":"505307852c79603a4fb65365ba36a617ff35522bb01114b2fafcc2142f314d091aaefd","path":"payload/chatroom-mcp-lite-patched.cjs","sha256":"a1abc812c52dcefeb85473275f7c1e5a86770b114767176416ed94ebe620cf00"}],"package_integrity":[{"filename":"0x2ai-demo1-2.0.2.tgz","hashes":{"sha512_sri":"sha512-uYBgzbYSPOLK/5apVkS6tdzsCv4gN6PO+5XOsFFXSV3wjvbd7KOMIQlL4ZuU76b504f/jwyNpvRJfJyMKcVQCA==","sha1":"5fba08011ef4181f4ac38fb45e374dc50d1cc3b7"}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}