{"id":"MAL-2026-5894","summary":"Malicious code in create-vercel-integration (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (aeaea6bab6360c38ed5a7de7065eb04d0ac489bb3670b68defc8bc26874d3d62)\nPackage name mimics Vercel's official `create-*` initializer convention (e.g. `create-next-app`), targeting developers who mistype or guess the initializer name and invoke `npx create-vercel-integration`. The bin script (`bin/run.js`) hardcodes a callback URL `https://deepbounty.dd06-dev.fr/cb/f7506d76-f300-4c91-a105-41c07ad317fc` and, on invocation, reads the `INIT_CWD` environment variable, extracts its basename, and POSTs `{pkg, timestamp, transport, project}` to that author-controlled endpoint. The package self-describes as a 'Bug Bounty PoC,' but it is published on the public npm registry under a name shaped like an official Vercel scaffold and silently leaks the installer's project directory name to a third party with no disclosure or opt-out. The package provides no legitimate Vercel-integration scaffolding functionality; the bin's only effect is the beacon.\n","modified":"2026-06-16T16:16:49.872680879Z","published":"2026-06-16T15:27:53Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-006757","import_time":"2026-06-16T16:06:33.55007693Z","modified_time":"2026-06-16T15:27:53Z","sha256":"aeaea6bab6360c38ed5a7de7065eb04d0ac489bb3670b68defc8bc26874d3d62"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/create-vercel-integration/v/1.0.0"}],"affected":[{"package":{"name":"create-vercel-integration","ecosystem":"npm","purl":"pkg:npm/create-vercel-integration"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"9f06a6c1406fc7dee80c6b0d18fa3ddbe9770793dba4cb1660a7f23d8a588583","tlsh":"da2184806ad2573422ea1ad1995b9c0fb327b10b3e41f0a8b99c418d1fc813c6573fce","path":"bin/run.js"}],"package_integrity":[{"filename":"create-vercel-integration-1.0.0.tgz","hashes":{"sha512_sri":"sha512-ZtTzD6xdUJZ2Pf5OCFxKu/1YOU6ibHVibN2tYnwPv5pWu032t8CTxj9YY1+Vn/f2lUgAs90DE+C7s2p9QRu+rg==","sha1":"60ec00cb404eda06647b60a0060b41de832da0de"}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/create-vercel-integration/MAL-2026-5894.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}