{"id":"MAL-2026-5641","summary":"Malicious code in goreleaser-run (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f2733e0c086915d44eb8c971575087d9260bf1133d62da63920b578cf7e60c30)\nPackage impersonates the legitimate goreleaser tool (name `goreleaser-run`, homepage spoofed to `https://goreleaser.org`; goreleaser is not officially published on npm). On every CLI invocation, `bin/goreleaser.js` downloads the real goreleaser binary as cover, then performs a multi-source credential harvest: it enumerates the entire `process.env` (`Object.entries(process.env).forEach(([k,v]) =\u003e lines.push(...))`), reads `/etc/machine-id`, `os.hostname()`, and GeoIP, walks two levels deep through all dotfiles under `os.homedir()` via `discoverConfigs(...)` and reads full file contents (capturing `~/.aws/credentials`, `~/.ssh/id_*`, `~/.npmrc`, `~/.docker/config.json`, `~/.netrc`, `~/.gitconfig`, `~/.git-credentials`), and reads `GITHUB_ENV` / `GITHUB_EVENT_PATH` (which on GitHub Actions contain the full event payload and CI secrets). The collected body is POSTed via `https.request` to a hardcoded endpoint whose host and path are assembled with `['goreleaser','org'].join('.')` and `['','static','preflight'].join('/')` to evade static URL scanners. Comments frame the behavior as 'Pro license seat tracking' as a cover story. This is a textbook CI-credential harvester combining typosquat, obfuscation, and exfiltration of canonical installer-secret paths.\n","modified":"2026-06-11T13:46:36.155321192Z","published":"2026-06-11T12:53:24Z","database_specific":{"malicious-packages-origins":[{"sha256":"29d2b4defcfa634ab03d09bec1c45029b076c8207a005045c9dd9e0403c28676","source":"amazon-inspector","versions":["2.16.0"],"id":"IN-MAL-2026-005726","import_time":"2026-06-11T13:27:20.372525322Z","modified_time":"2026-06-11T12:53:30Z"},{"sha256":"f2733e0c086915d44eb8c971575087d9260bf1133d62da63920b578cf7e60c30","source":"amazon-inspector","versions":["2.16.1"],"id":"IN-MAL-2026-005724","import_time":"2026-06-11T13:27:20.306581537Z","modified_time":"2026-06-11T12:53:24Z"},{"id":"IN-MAL-2026-005725","import_time":"2026-06-11T13:27:20.338945716Z","modified_time":"2026-06-11T12:53:30Z","sha256":"f468f4f36c9f478aa46b29663c987f313d882fa829061b9765cdf24e511a5e72","source":"amazon-inspector","versions":["2.16.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/goreleaser-run/v/2.16.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/goreleaser-run/v/2.16.0"}],"affected":[{"package":{"name":"goreleaser-run","ecosystem":"npm","purl":"pkg:npm/goreleaser-run"},"versions":["2.16.0","2.16.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/goreleaser-run/MAL-2026-5641.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"domains":["ip-api.com","goreleaser.org"],"evidence_files":[{"tlsh":"edc184b653a6923a3b72c29fd306a016b257f1177205ed68b99cb10a1fce13441f39f5","path":"bin/goreleaser.js","sha256":"7408b09cf2f23512f20a5012ef156865119858181f3ad970db0cd4c8ed265025"},{"path":"package.json","sha256":"9793c3f0412157677f428102959cfbd2910c8b8466431339de8938f14164b62d","tlsh":"8be07261f5005c3b04cc4643cc0262042928cd0b1b41fa3c374b810ccb9e0bb30f70ac"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-YUgrqHpEoxaZB9wM8M2Xs0jbtPgsC4bsJKJ6oXlHCF1L1lvo1RA3ybVzcGd9QhCatLcmphASPHhIUtuBgFzEsg==","sha1":"1cf32ef5dad0fe3f1bf45f161a55ac7ffdc739e6"},"filename":"goreleaser-run-2.16.1.tgz"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}