{"id":"MAL-2026-5751","summary":"Malicious code in oh-my-ashclaw (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (daf0a5a6234cbf55718057017cbe143ab41ad1aaf7964ebfaab6dfe12703b005)\nOn `npm install`, the package's postinstall hook `.prepare.cjs` executes and harvests installer-side data: hostname, username, OS/arch, Node version, all non-internal network interface IPs, the configured npm registry, and a complete dump of `process.env` (filtered only to drop `npm_lifecycle*` keys). This payload is HTTPS POSTed in Lark message format to `open.larksuite.com`, whose hostname is decoded at runtime from a numeric charcode array using a reverse-and-subtract-7 cipher (`_hostDecoder([116,118,106,53,...])` → `open.larksuite.com`); the URL path is separately XOR-decoded with key `Zk9x`. Cover-story comments label the script 'Build Environment Telemetry'. The full env dump captures any developer/CI secrets present in the shell (`GITHUB_TOKEN`, `NPM_TOKEN`, `AWS_ACCESS_KEY_ID`/`AWS_SECRET_ACCESS_KEY`, cloud provider keys, internal URLs, arbitrary CI variables). The script also implements aggressive anti-analysis: it silently `process.exit(0)`s when it detects honeypot env vars (`PYPI_POISON_HONEY_TOKEN`, `PYPI_POISON_AUDIT_LOG_NODE`, `PP_ARTIFACT_SHA256`, `THREAT_ANALYZER_MODEL`, `ASPECT_TLOG`, `MUADDIB_GVISOR`), sandbox env-var prefixes (`SANDYCLAW_`, `OPENCLAW_`, `PERMISO_`, `CHAINRADAR_`), `NODE_OPTIONS` injecting `-r`, specific test AWS keys, hostnames matching `detonat|cuckoo|virus|scan|chainradar`, sandbox usernames, `HOME` containing `openclaw`, and CI count \u003e=3. The package name and description ('Inspired by oh-my-opencode') target users of the legitimate `oh-my-opencode` ecosystem, and `repository.url` is the placeholder `git+https://github.com/your-repo/oh-my-ashclaw.git`. This is unambiguous malicious supply-chain code: bulk credential-scraping exfiltration over an obfuscated channel with deliberate evasion of named threat-analysis platforms.\n","modified":"2026-06-13T21:46:45.576278020Z","published":"2026-06-13T20:59:00Z","database_specific":{"malicious-packages-origins":[{"sha256":"1eea8d9a73fc4dce5669cb1b347d083ea5defb353006a5bf7321fdcc36ae3bff","source":"amazon-inspector","versions":["4.11.2"],"id":"IN-MAL-2026-006395","import_time":"2026-06-13T21:32:33.073857491Z","modified_time":"2026-06-13T20:59:01Z"},{"source":"amazon-inspector","versions":["4.11.2"],"id":"IN-MAL-2026-006394","import_time":"2026-06-13T21:32:33.028078715Z","modified_time":"2026-06-13T20:59:00Z","sha256":"daf0a5a6234cbf55718057017cbe143ab41ad1aaf7964ebfaab6dfe12703b005"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/oh-my-ashclaw/v/4.11.2"}],"affected":[{"package":{"name":"oh-my-ashclaw","ecosystem":"npm","purl":"pkg:npm/oh-my-ashclaw"},"versions":["4.11.2"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"oh-my-ashclaw-4.11.2.tgz","hashes":{"sha1":"4e45a9652fb125518d31d9fcbe51e151682c7568","sha512_sri":"sha512-2yfuJEQKlHVmIdkihvYl5NSTQUD8ZHcsB9xA6GQHLGc6wsPnFHqRZjL1cOfqjEoy5ZchjYBVcn2jKtfP5ao+Eg=="}}],"domains":["github.com"],"evidence_files":[{"path":".prepare.cjs","sha256":"d17157828b17732d1577bf74528962b924d57f28f238f5df8fe3c31411ae84a4","tlsh":"ade131ced3a11ae5ab5108a3841e750a58b8c1231d2d92d8bcd4c2d77ff5b7056aa3fc"},{"tlsh":"6081fb34dc26ceb31bc418a279749251f1659467ce59f803b3caa26d0f8d19f21bba2d","path":"package.json","sha256":"6fea38e545b146c37bf21b8810e101ceb457fac7d056d5383b0fae95e45c11c0"}],"ips":["140.82.114.3"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/oh-my-ashclaw/MAL-2026-5751.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}