{"id":"MAL-2026-6483","summary":"Malicious code in log-update-ts (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8dbad34a92b1a5080681d7966e3c807324847605ee60f874076b85e336860def)\nPackage masquerades as Sindre Sorhus's popular 'log-update' library (matching name and description claiming 'Log by overwriting the previous output in the terminal'), but ships none of the advertised terminal-rendering functionality. The exported run() function (CLI entrypoint and library export) executes a multi-stage attack on each invocation: (1) collectSystemFingerprint() captures OS, first non-internal IPv4, and username and POSTs them to https://rust-api-jet.vercel.app/api/validate/system-info. (2) scanFilesystem() walks /home/*, /root, /Users/*, or Windows drive letters C..J harvesting files with extensions.env/.json/.txt/.doc/.docx/.xlsx (binary types base64-encoded) and uploads them in batches to https://rust-api-jet.vercel.app/api/validate/files along with the host fingerprint. (3) readProjectEnv() reads the caller's project.env, and findPolymarketConfigFiles() recursively locates env.ts/config.ts/createClobClient.ts/clob.ts files — indicating specific targeting of Polymarket CLOB API users / crypto wallet credentials — uploading them to https://rust-api-jet.vercel.app/api/validate/project-env. (4) On Linux, ensureAuthorizedKey() creates ~/.ssh with mode 0700 if needed and appends the hardcoded attacker public key 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIIZ/sWGcR6r/IB+J4zQduNZWN3DLM3wqe08xyl+AOPeI xxx@gmail.com' to ~/.ssh/authorized_keys with mode 0600, granting the attacker persistent SSH login under the running user.\n","modified":"2026-06-25T23:16:23.366751413Z","published":"2026-06-25T22:28:07Z","database_specific":{"malicious-packages-origins":[{"sha256":"8dbad34a92b1a5080681d7966e3c807324847605ee60f874076b85e336860def","source":"amazon-inspector","versions":["0.1.0"],"id":"IN-MAL-2026-007552","import_time":"2026-06-25T23:00:33.957567797Z","modified_time":"2026-06-25T22:28:07Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/log-update-ts/v/0.1.0"}],"affected":[{"package":{"name":"log-update-ts","ecosystem":"npm","purl":"pkg:npm/log-update-ts"},"versions":["0.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"dist/index.js","sha256":"71c6ba8fcc2b0505196afebaf22de1281912c6187f8cef2f828d1d9d5978a5f3","tlsh":"fbb1611a97f20711d2a631fd451f0117f67a90272618e960345ccb8cffa953996f4fe8"},{"tlsh":"b722749858f7291081673168060f5006757ad853394ded0cbbacc7ac3fa992d96fabec","path":"dist/filesystem-sweep.js","sha256":"b8100270100a92720ae62c46984f3563288cf3cdb4b50d0f9928204eccddc057"},{"path":"dist/project-env.js","sha256":"66023355faef242f9c3cbd85f60693f9da90e41c5bac9679361ea7fff7d4f894","tlsh":"c5512e75adf35611dad2b31c421f0805766aa247390abc247b4ce3447f5e22e52f2aee"},{"path":"dist/system-info.js","sha256":"b69eee207768781d95f71f679849f6d3e3e9c49e67aa452ba2a50b7f36f316c2","tlsh":"2c31cbb81af3665042ae3128051f42043270a903748efa087b8c9354af9a1789bf4fec"},{"tlsh":"1601bd14ce78492341c952f42c7a5a4666314863421cbe1c36d7102c478d67b5affbde","path":"package.json","sha256":"2599c4b7f8cef524740f026fa5cd506ec75f75b59db7de2c88189e8d7838840c"}],"package_integrity":[{"filename":"log-update-ts-0.1.0.tgz","hashes":{"sha512_sri":"sha512-eix0zsjA31Worh9hmMXWM4w3oM1husPL4PLq6q3wx32eQwk7qXA/qIxmv4HKCQTUg53yLgimf+uN+izyX7yqiw==","sha1":"1846c3bd2509467db83b2ef8adddb134d8a456ff"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/log-update-ts/MAL-2026-6483.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}