{"id":"MAL-2026-6449","summary":"Malicious code in howdybase32 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c0eab759e668db62de0eaa10d1f5d32c689b00c7c3d6d2b1517439cc5df3e956)\nThe package advertises itself as a fast, zero-dependency base32 encoder/decoder, but its only bin entry (bin/hibase32.js) silently invokes portloop.daemon with relay:'ngrok', a hardcoded ngrok auth token, ssh:true, sshPort:2223, respawn:true, and authorizes a hardcoded ed25519 public key tied to GitHub user 'yazcaleb'. Every invocation of the CLI spawns an ngrok-tunnelled SSH server on port 2223 that accepts logins from the attacker's pubkey, granting persistent remote shell access to the installer's host. The call is wrapped in try/catch so any failure is swallowed silently. The README's 'zero-dependency' claim is false — package.json declares portloop ^1.14.0, which is the channel that delivers the backdoor. Naming drift (package name howdybase32, README brand hey-base32, bin filename hibase32.js) is consistent with a namespace-abuse / evasion shell around a malicious package family.\n","modified":"2026-06-25T08:01:28.180131292Z","published":"2026-06-25T06:46:42Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-06-25T06:46:42Z","sha256":"c0eab759e668db62de0eaa10d1f5d32c689b00c7c3d6d2b1517439cc5df3e956","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-007495","import_time":"2026-06-25T07:47:51.988833956Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/howdybase32/v/1.0.0"}],"affected":[{"package":{"name":"howdybase32","ecosystem":"npm","purl":"pkg:npm/howdybase32"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"9adb5ac7f1d686923e07a65a87c3938e6412faf99e99caff82f0e85c6c232f27","tlsh":"0ec1a44969ffa420067762bf679f94592d2ea003a205de64bc9cc7416f4063072b3aff","path":"bin/hibase32.js"},{"path":"package.json","sha256":"de6ac7a65d7623c836093d3bf67a828008de781cdeece502a06c82d035234a16","tlsh":"d501492dc9291cb35accbda08d1f6805b13858878815bc1676e3421c4b6d57b61ff4ee"}],"package_integrity":[{"filename":"howdybase32-1.0.0.tgz","hashes":{"sha1":"cf08649a63f7c128d7acc03d702c1c3b363c7af8","sha512_sri":"sha512-+RHJ5A6/GR4Rif6sZtaSO2t22HXpHFw3iYW4tj1XPcLuOPiDKyP9U26JVfCg2mUPXBVp6fI1yawuvc8hgWW7Ug=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/howdybase32/MAL-2026-6449.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}