MAL-2026-12797Malicious code in multi-reqs (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | multi-reqs | 1.0.0 |
| npm | multi-reqs | 1.0.1 |
| npm | multi-reqs | 1.0.2 |
| npm | multi-reqs | 1.0.3 |
{"schema_version":"1.7.4","id":"MAL-2026-12797","published":"2026-08-05T13:19:10Z","modified":"2026-08-05T16:16:03.465389682Z","summary":"Malicious code in multi-reqs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce)\nThe package's default export accepts (token, password) arguments and POSTs them, formatted as a Discord embed titled 'Yeni Hesap Bilgisi' with fields '🔑 Token' and '🔒 Şifre', to a hardcoded discord.com webhook URL. The destination is non-configurable, and any consumer that imports multi-reqs and invokes the default function forwards those credentials to an author-controlled Discord channel. Parameter naming and the Turkish 'Hesap Yönetim Sistemi' (Account Management System) framing indicate the module is designed to be consumed or bundled into other code as a credential-harvesting shim.\n","affected":[{"package":{"name":"multi-reqs","ecosystem":"npm"},"versions":["1.0.2","1.0.3","1.0.0","1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"7cc40c2f862b243fdba1922cc830bee717b39f6368d4812dd0cd8328fceaeddc","tlsh":"cc01449fd8bb09a18807bd569e4f80002319e0570c1bac74bbdcc3194fed82d58f2698"}],"package_integrity":[{"filename":"multi-reqs-1.0.2.tgz","hashes":{"sha1":"3d01007ae24582630cef1ee681590a98c8215acc","sha512_sri":"sha512-qbzYlS7jCHKsBSfWaH8HWU71TekI4mt2/4/RhFWkGSUBe5o6kc2rUECV3MGcKJIvQni75xrKlITKEVS5VR23uQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/multi-reqs/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/multi-reqs/v/1.0.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/multi-reqs/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/multi-reqs/v/1.0.1"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014971","import_time":"2026-08-05T14:19:48.089416611Z","modified_time":"2026-08-05T13:19:10Z","sha256":"2c03bde07a2a75531f18734b6986de0c59cd7d75400c665e4e059fb18b42996f","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-014973","import_time":"2026-08-05T14:19:48.263489273Z","modified_time":"2026-08-05T13:19:24Z","sha256":"633363514a8110d1ba6af50ac4431fa5e3bccb5e3692222d856747f10e6397ac","source":"amazon-inspector","versions":["1.0.3"]},{"id":"IN-MAL-2026-014974","import_time":"2026-08-05T14:19:48.362582657Z","modified_time":"2026-08-05T13:19:31Z","sha256":"a3d70b2617fc2d0158533bc541e04b68263a1e07ee2057c439c43ec40b073ad4","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-015797","import_time":"2026-08-05T16:13:46.256938358Z","modified_time":"2026-08-05T15:41:46Z","sha256":"38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce","source":"amazon-inspector","versions":["1.0.1"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0