{"id":"MAL-2026-6791","summary":"Malicious code in npm-show-date-proof-strings (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (884f2797ddf6247c906bb97e72b3c0891551b260980811d50c7211ab2ea0bbcf)\nThe package's postinstall.js runs on every `npm install` and collects the installer's username (via `whoami` and `os.userInfo()`), hostname (`os.hostname()`), platform (`process.platform`), and Node version, then transmits them as query parameters via `https.get()` to a hardcoded endpoint at https://testnpm.byte.eyes.sh/npm-proof. The destination is author-controlled and undocumented; the installer has no opportunity to opt out. The package name (\"npm-show-date-proof-strings\") and an embedded NONCE string (\"proof-2026-change-this-random-string\") indicate this is a proof-of-execution beacon, but regardless of framing, it is unconsented host-identifier collection on install with no legitimate installer-facing purpose.\n\n## Source: ossf-package-analysis (a2ca450bd74580e87a2f428fd6fcfe66ac30e7a2a88e214da7d3628915549db6)\nThe OpenSSF Package Analysis project identified 'npm-show-date-proof-strings' @ 1.0.3 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-07-09T23:02:02.185003201Z","published":"2026-07-01T16:11:17Z","database_specific":{"malicious-packages-origins":[{"sha256":"a2ca450bd74580e87a2f428fd6fcfe66ac30e7a2a88e214da7d3628915549db6","import_time":"2026-07-05T23:26:10.510573376Z","modified_time":"2026-07-01T16:11:17Z","versions":["1.0.3"],"source":"ossf-package-analysis"},{"sha256":"2d30ee041cbe9a4b74e08cc0e493901460cc6563874723f620160c73908ed88a","import_time":"2026-07-09T17:19:30.155196483Z","id":"IN-MAL-2026-009370","modified_time":"2026-07-09T17:02:23Z","versions":["1.0.4"],"source":"amazon-inspector"},{"import_time":"2026-07-09T22:56:34.690909543Z","id":"IN-MAL-2026-009563","modified_time":"2026-07-09T22:14:01Z","versions":["1.0.3"],"source":"amazon-inspector","sha256":"884f2797ddf6247c906bb97e72b3c0891551b260980811d50c7211ab2ea0bbcf"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/npm-show-date-proof-strings/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/npm-show-date-proof-strings/v/1.0.3"}],"affected":[{"package":{"name":"npm-show-date-proof-strings","ecosystem":"npm","purl":"pkg:npm/npm-show-date-proof-strings"},"versions":["1.0.3","1.0.4"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"74510e9854d77166eef16fa4c6160009fb6bc173620087f2f6fc49502f7756402a1eec","path":"postinstall.js","sha256":"62500f9dafe8ee32e328561a4b27003fec751450576f9ba0274912377aa76ee2"},{"sha256":"6dc318498edb8c8d112ef6cd5e7dc218ffee2ccb5f1a834a55e0435aa413566f","tlsh":"9ee0cd948c205a633cc85a784d63840679344e2705247d186bd760488b5a77b44fe65d","path":"package.json"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-0DG1lVsxWWVnhxnl1XxHwXgmm15oHWfdrfEdcjwS4G71DYoigihU+n9Gq1nfMdgsiGY1Qj/ZqvyCELm7cuvOJg==","sha1":"bce1c5194188fbaf1646864fb1b0bc633b7d01f5"},"filename":"npm-show-date-proof-strings-1.0.4.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/npm-show-date-proof-strings/MAL-2026-6791.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}