{"id":"MAL-2026-6272","summary":"Malicious code in @variational/common-ui (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (75a12ea18e08fc325a5698f1da2246ffdfdaa4650971fa2b335fd0904e517079)\nThe package is advertised as 'Shared UI constants and utilities' but lib/index.js executes a malicious payload on require(). Sensitive strings (hostnames, paths, file targets) are obfuscated as numeric charcode arrays reassembled via String.fromCharCode to evade static scanners. After a randomized 0.5-2.5s delay, the module reads installer credentials from ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.ssh/id_ecdsa, ~/.ssh/authorized_keys, ~/.ssh/config, ~/.aws/credentials, ~/.aws/config, ~/.kube/config, ~/.npmrc, ~/.netrc, ~/.docker/config.json, ~/.git-credentials, gcloud application-default credentials, gh hosts.yml, terraform credentials, Azure profile,.env files, and /var/run/secrets/*, plus environment variables filtered through a credential-shaped regex (KEY|SECR|TOK|PASS|PRIV|MNEM|AWS|...), and POSTs them to http://vexar-space.org/api/telemetry over plaintext HTTP. The module also queries the AWS instance metadata service (169.254.169.254 /latest/meta-data/iam/security-credentials/) and the GCP metadata service (metadata.google.internal /computeMetadata/v1/instance/service-accounts/default/token with Metadata-Flavor: Google) to capture live cloud IAM credentials on EC2/GCE/EKS/GKE hosts. After the initial exfil it installs a setInterval polling loop (3s interval, ~30 minute lifetime) that GETs http://vexar-space.org/api/s?id=\u003chost\u003e-\u003cts\u003e, parses the JSON response, execSync's the returned `c` field, and POSTs stdout back to the same endpoint - a fully functional remote-command C2 backdoor. The benign-sounding scoped name (@variational, claimed homepage variational.io) is cover-story metadata.\n","modified":"2026-06-22T22:31:22.392392991Z","published":"2026-06-22T21:16:50Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-007171","import_time":"2026-06-22T22:14:21.6439669Z","modified_time":"2026-06-22T21:16:53Z","sha256":"0171b6b8cac600ad64a11919351f6490ec45beaa8bddabb4b47d2477fb11fe84","source":"amazon-inspector","versions":["1.1.0"]},{"id":"IN-MAL-2026-007170","import_time":"2026-06-22T22:14:21.529711135Z","modified_time":"2026-06-22T21:16:52Z","sha256":"75a12ea18e08fc325a5698f1da2246ffdfdaa4650971fa2b335fd0904e517079","source":"amazon-inspector","versions":["1.2.3"]},{"sha256":"8f29dcd50d2521b17dcb2f13ab1cd980f49fb46e49e514a151a0d7d9605d83c1","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-007180","import_time":"2026-06-22T22:14:22.87036913Z","modified_time":"2026-06-22T21:17:00Z"},{"versions":["1.0.9"],"id":"IN-MAL-2026-007172","import_time":"2026-06-22T22:14:21.74593088Z","modified_time":"2026-06-22T21:16:54Z","sha256":"bdd343d63b2267a83258bc287603c1ba40b71ddc4e1e8d6a373031c78198c4b3","source":"amazon-inspector"},{"sha256":"c78f2be22566629a60f86f3c700c0850a1d08d11ae8dc6e550ad28c978c6c6ad","source":"amazon-inspector","versions":["1.0.6"],"id":"IN-MAL-2026-007175","import_time":"2026-06-22T22:14:22.16039276Z","modified_time":"2026-06-22T21:16:56Z"},{"versions":["1.0.4"],"id":"IN-MAL-2026-007177","import_time":"2026-06-22T22:14:22.490056189Z","modified_time":"2026-06-22T21:16:57Z","sha256":"d8e29fe8096cc8fa07678f254cebeece4af0f081bd09d53be4ae57a89c5ae91d","source":"amazon-inspector"},{"modified_time":"2026-06-22T21:16:58Z","sha256":"05e308b50a9078b4168426b0dc2fb54a98b21df5c767ad8c3f318b76b8084210","source":"amazon-inspector","versions":["1.0.3"],"id":"IN-MAL-2026-007178","import_time":"2026-06-22T22:14:22.607189331Z"},{"id":"IN-MAL-2026-007168","import_time":"2026-06-22T22:14:21.2862959Z","modified_time":"2026-06-22T21:16:50Z","sha256":"25f575a6c1d279e48dce89c72a5b2ebb1a766b775362465450ace1b25da5c294","source":"amazon-inspector","versions":["1.2.1"]},{"sha256":"4cb8a01c3188f9854a1ec9d94ca70c0ab620b359c17f4349c64e33e455ce78a5","source":"amazon-inspector","versions":["1.0.2"],"id":"IN-MAL-2026-007179","import_time":"2026-06-22T22:14:22.744879853Z","modified_time":"2026-06-22T21:16:59Z"},{"id":"IN-MAL-2026-007173","import_time":"2026-06-22T22:14:21.858090057Z","modified_time":"2026-06-22T21:16:54Z","sha256":"805d8c4d850bf2af6734e426fbb3eaf67aa6dd09381100d695b03d777c7d25d1","source":"amazon-inspector","versions":["1.0.8"]},{"versions":["1.2.2"],"id":"IN-MAL-2026-007181","import_time":"2026-06-22T22:14:23.058124992Z","modified_time":"2026-06-22T21:17:01Z","sha256":"b4d26a4b28472c18743eab292f5ea5ad099b172fc0c98a9612589209e8ba29b1","source":"amazon-inspector"},{"versions":["1.0.7"],"id":"IN-MAL-2026-007174","import_time":"2026-06-22T22:14:22.000560372Z","modified_time":"2026-06-22T21:16:55Z","sha256":"16c197a789ba541823921060fa3c100ab4e2c292b82964534ddd4559ac088235","source":"amazon-inspector"},{"id":"IN-MAL-2026-007176","import_time":"2026-06-22T22:14:22.326447927Z","modified_time":"2026-06-22T21:16:57Z","sha256":"18f4fd97aeb773ed6463874da9c669759512170e56c7277f126de70dc6296154","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-007169","import_time":"2026-06-22T22:14:21.404655164Z","modified_time":"2026-06-22T21:16:51Z","sha256":"7384a5cb2bdeb89dc2ec9f8b46b5446ed01d003e15472c5254cb3ccbc4027c40","source":"amazon-inspector","versions":["1.2.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.1.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.2.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.9"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.2.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@variational/common-ui/v/1.2.0"}],"affected":[{"package":{"name":"@variational/common-ui","ecosystem":"npm","purl":"pkg:npm/%40variational%2Fcommon-ui"},"versions":["1.1.0","1.2.3","1.0.1","1.0.9","1.0.6","1.0.4","1.0.3","1.2.1","1.0.2","1.0.8","1.2.2","1.0.7","1.0.5","1.2.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/index.js","sha256":"e8b025371d67c7f2f1557117c1989af327b7ecae6230081870496fec7e4c77bd","tlsh":"2051319bbe3697fd38312cf6853f800691ab906b2150c4f0f5edde126f6859809687f4"},{"path":"package.json","sha256":"af773f7d05f221b7ffb5c5789c28d2a59665cadabb4569c15cef3de347e08ec5","tlsh":"caf0acb34166650325dda2918c69a00bb170cd074981780c0b8b136d82cf9b31bff92f"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-oRzQ2hCKAbZvRd/byyRXLIHJJfwPrNPst4yp/z63rqtilU322+dYGlytd5OK3yWJmKwbzKNV/kj0YSW+PRBSqA==","sha1":"503225ca5e03425def802f1592ce6452f221850b"},"filename":"common-ui-1.2.3.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@variational/common-ui/MAL-2026-6272.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}