MAL-2025-6894Malicious code in commonweb-flow (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | commonweb-flow | 1.0.0 |
| npm | commonweb-flow | 10.11.0 |
| npm | commonweb-flow | 10.12.0 |
| npm | commonweb-flow | 10.13.0 |
| npm | commonweb-flow | 10.14.0 |
| npm | commonweb-flow | 10.15.0 |
| npm | commonweb-flow | 5.8.999 |
| npm | commonweb-flow | 5.999.999 |
| npm | commonweb-flow | 6.0.999 |
| npm | commonweb-flow | 6.999.999 |
| npm | commonweb-flow | 7.1.999 |
| npm | commonweb-flow | 7.2.999 |
| npm | commonweb-flow | 7.3.999 |
| npm | commonweb-flow | 7.999.999 |
| npm | commonweb-flow | 99.99.99 |
{"schema_version":"1.7.4","id":"MAL-2025-6894","published":"2025-08-17T11:40:41Z","modified":"2026-08-06T23:29:18.537524652Z","summary":"Malicious code in commonweb-flow (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e116400179d508d6dbe723a75f049d05218e1b019474bca84f2ed62537219572)\ncommonweb-flow@7.999.999 declares its sole dependency `linker-event-header-serial` as a direct tarball URL on `artifacts.yosiroute.com` (not the npm registry), and npm-shrinkwrap.json marks that dependency with `hasInstallScript: true`. On `npm install`, npm fetches the tarball from `artifacts.yosiroute.com` and runs its lifecycle install scripts, giving that host arbitrary code execution on the installer's machine. The tarball contents at that URL are mutable and can be swapped server-side without republishing commonweb-flow. Package metadata is placeholder (`author: \"Package Registry\"`, `description: \"Generated package\"`, repository `github.com/example/commonweb-flow`), and the manifest version `7.999.999` is inflated relative to the README/index.js self-reported `1.0.0` — the shape of a dependency-confusion lure aimed at internal builds that resolve `commonweb-flow` from the public registry over an internal package of the same name.\n\n## Source: ossf-package-analysis (0062bd72b843a0cab680d5655259ce9502b602bf366057232de9469f99b853e3)\nThe OpenSSF Package Analysis project identified 'commonweb-flow' @ 10.11.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","affected":[{"package":{"name":"commonweb-flow","ecosystem":"npm"},"versions":["10.11.0","10.14.0","10.12.0","10.15.0","10.13.0","7.3.999","7.1.999","5.8.999","7.2.999","99.99.99","5.999.999","6.0.999","7.999.999","1.0.0","6.999.999"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"npm-shrinkwrap.json","sha256":"2f0047728607d14fb839cbe99c597e4e8005f5cc0d0b7b7f845e895b78c2f9b8","tlsh":"6cf0f0b1cca81eb321e823b4c13a59029660210b8d1c38ddfacc5c1d4fd8dab29a4708"}],"package_integrity":[{"filename":"commonweb-flow-7.3.999.tgz","hashes":{"sha1":"cee0fe7280f107f99020820d1a6423d6f4d82f43","sha512_sri":"sha512-qYJcPPMlIQd4gifP7ow/n3wWer813HjLnfBa50rkaBEpuUmI9mEKvLa9Bx1HUCHHGWJevP+p73zaF9qmCUoCBQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/7.3.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/7.1.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/5.8.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/7.2.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/99.99.99"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/5.999.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/6.0.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/7.999.999"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/commonweb-flow/v/6.999.999"}],"database_specific":{"malicious-packages-origins":[{"import_time":"2025-08-17T12:09:34.703644367Z","modified_time":"2025-08-17T11:40:41Z","sha256":"0062bd72b843a0cab680d5655259ce9502b602bf366057232de9469f99b853e3","source":"ossf-package-analysis","versions":["10.11.0"]},{"import_time":"2025-08-17T13:39:32.252171071Z","modified_time":"2025-08-17T13:30:55Z","sha256":"5bcd8577706d27ca6cc5252f85e422508cda0b5d6bda71ea5df868bca41c8a6f","source":"ossf-package-analysis","versions":["10.14.0"]},{"import_time":"2025-08-17T13:39:32.147893047Z","modified_time":"2025-08-17T13:14:33Z","sha256":"d9b58be14f6055e5d3650c12e54f16ecde2ff0ba9c8587d272b918c4277229ff","source":"ossf-package-analysis","versions":["10.12.0"]},{"import_time":"2025-08-17T15:36:02.520090251Z","modified_time":"2025-08-17T15:28:34Z","sha256":"04684d4086c4313003ed0e06c85458352f5ca435bf592fd6001b90e4c67911a7","source":"ossf-package-analysis","versions":["10.15.0"]},{"import_time":"2025-08-18T06:09:46.728370718Z","modified_time":"2025-08-17T13:27:04Z","sha256":"bdc5595e1f21ceb733d6e936051dec79d1b46e18698930b33b7eb6f6dba7ddbd","source":"ossf-package-analysis","versions":["10.13.0"]},{"id":"IN-MAL-2026-016706","import_time":"2026-08-06T18:09:08.890131201Z","modified_time":"2026-08-06T16:27:50Z","sha256":"3c5fee00c8d8c3cf5f6caac853392e3b514f4eb82b2cc45e8a3e52bc381b0523","source":"amazon-inspector","versions":["7.3.999"]},{"id":"IN-MAL-2026-016708","import_time":"2026-08-06T18:09:09.170148989Z","modified_time":"2026-08-06T16:28:51Z","sha256":"469d3048080e379125d121adb4fc041b0b37fb0f52f4ca0d9d8c243b2c134114","source":"amazon-inspector","versions":["7.1.999"]},{"id":"IN-MAL-2026-016710","import_time":"2026-08-06T18:09:09.407251715Z","modified_time":"2026-08-06T16:33:51Z","sha256":"dc1d6f97961c2f3d72f3517914a0b48ce1a0e0a9a449802c28391a71a8ab9a10","source":"amazon-inspector","versions":["5.8.999"]},{"id":"IN-MAL-2026-016707","import_time":"2026-08-06T18:09:09.018902737Z","modified_time":"2026-08-06T16:28:00Z","sha256":"175f96f7b6e528c0dd0d28d14f1d38d98e1be928ed6cef84ad11a54b04694b18","source":"amazon-inspector","versions":["7.2.999"]},{"id":"IN-MAL-2026-016666","import_time":"2026-08-06T18:09:03.301689125Z","modified_time":"2026-08-06T16:14:55Z","sha256":"a18ec07b1b3b6d69d628b180b0de1bdff6ba47f233392864581283a6305ff7fa","source":"amazon-inspector","versions":["99.99.99"]},{"id":"IN-MAL-2026-016713","import_time":"2026-08-06T18:09:09.888958016Z","modified_time":"2026-08-06T16:34:20Z","sha256":"a6f05daa5f51d4a63e9461b29c3cc3a224ac09378e11eb1f09ae00e0a27cc8f0","source":"amazon-inspector","versions":["5.999.999"]},{"id":"IN-MAL-2026-016712","import_time":"2026-08-06T18:09:09.684430559Z","modified_time":"2026-08-06T16:34:10Z","sha256":"ad3636aaffaf4f15c191a2052a1a7f0afdd0bad2c17594e49f1013f4e9e3ab91","source":"amazon-inspector","versions":["6.0.999"]},{"id":"IN-MAL-2026-016705","import_time":"2026-08-06T18:09:08.764127823Z","modified_time":"2026-08-06T16:27:40Z","sha256":"e116400179d508d6dbe723a75f049d05218e1b019474bca84f2ed62537219572","source":"amazon-inspector","versions":["7.999.999"]},{"id":"IN-MAL-2026-016711","import_time":"2026-08-06T18:09:09.547956646Z","modified_time":"2026-08-06T16:34:01Z","sha256":"e94f68cb062c09a675b899a7932554c5913ff1e0466f9f0ae6d1d97da4e1aa7b","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-016709","import_time":"2026-08-06T18:09:09.300879581Z","modified_time":"2026-08-06T16:33:44Z","sha256":"3a38588a53eae4c3aa491d5f9dc61d2cc6e2801cce35a33ad1b8800b950dd189","source":"amazon-inspector","versions":["6.999.999"]}]},"credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com","inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0