{"id":"MAL-2026-5764","summary":"Malicious code in sys-info-cli-app (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1423c435a0e9e86338dd64d138fb1697580751ade2b7486880e21785e1b3eb47)\nThe package's collect.js gathers host identifiers (os.hostname(), os.homedir()) along with filesystem and child_process introspection and POSTs them to a hardcoded external endpoint at http://aab.sportsontheweb.net. The destination is unrelated to any legitimate npm distribution infrastructure and the data flow has no documented purpose tied to the package's stated function. The combination of os/child_process/fs reads with an outbound POST to an attacker-controlled domain is the canonical host-reconnaissance / exfiltration shape. Installing or loading this package causes installer host metadata to be sent off-host to a third-party server.\n","modified":"2026-06-14T08:01:43.702496733Z","published":"2026-06-14T07:21:56Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-006454","import_time":"2026-06-14T07:43:27.690315636Z","modified_time":"2026-06-14T07:21:58Z","sha256":"1423c435a0e9e86338dd64d138fb1697580751ade2b7486880e21785e1b3eb47","source":"amazon-inspector"},{"id":"IN-MAL-2026-006455","import_time":"2026-06-14T07:43:27.722977593Z","modified_time":"2026-06-14T07:21:59Z","sha256":"27dfc1e117001fe5c9c5ba1d091d3dfb7221dcba8548a0d9de5782f1ba878177","source":"amazon-inspector","versions":["1.0.1"]},{"versions":["1.0.9"],"id":"IN-MAL-2026-006456","import_time":"2026-06-14T07:43:27.756683818Z","modified_time":"2026-06-14T07:21:59Z","sha256":"59aa09b82f37f5407f4b9f36e747cf77223ec561e131c5e6a910037d824c32ae","source":"amazon-inspector"},{"modified_time":"2026-06-14T07:21:56Z","sha256":"64659c05718995ad539dc101e0c177c8f663dce920935b1e8cf39ea11914e840","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-006452","import_time":"2026-06-14T07:43:27.575350736Z"},{"modified_time":"2026-06-14T07:21:58Z","sha256":"a4e883a7d23f25424d56280dc14ad8a08a163ef7c9c01b12689ae8049899a617","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-006453","import_time":"2026-06-14T07:43:27.64038548Z"},{"modified_time":"2026-06-14T07:21:59Z","sha256":"b3eec1fa6a56319409ac7aaf6de49d64ff54b6d70c50dfe1a8083da345e3a32d","source":"amazon-inspector","versions":["1.0.9"],"id":"IN-MAL-2026-006457","import_time":"2026-06-14T07:43:27.790539379Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/sys-info-cli-app/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sys-info-cli-app/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/sys-info-cli-app/v/1.0.2"}],"affected":[{"package":{"name":"sys-info-cli-app","ecosystem":"npm","purl":"pkg:npm/sys-info-cli-app"},"versions":["1.0.1","1.0.9","1.0.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"ips":["104.16.1.34","10.1.0.2","104.16.10.34","104.16.4.34"],"package_integrity":[{"filename":"sys-info-cli-app-1.0.1.tgz","hashes":{"sha1":"0aad8a32ba5e24772315847a5d6c7fa01c9f91b9","sha512_sri":"sha512-YFffdBmy2dPVUHhlB4JrDx1zi0Y9Ax8/ffv/Mo2vkcnFoUGwjOz9n5h8SVxA3ysHLWaL+A/S4mOuMePQjWOuag=="}}],"evidence_files":[{"path":"collect.js","sha256":"463735e1a5b9150efad9ef66856033363d7ffb55490e84d1bf450c0e1406ef4d","tlsh":"44a21e5b14cb351ac747e70ad7670014ad88abb3b113bb41bb8c9bd41f2ad2662d09f9"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sys-info-cli-app/MAL-2026-5764.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}