MAL-2026-13358Malicious code in app-kst-engine (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | app-kst-engine | 2.1.6 |
{"modified":"2026-08-05T17:22:35Z","published":"2026-08-05T17:22:35Z","schema_version":"1.7.4","id":"MAL-2026-13358","summary":"Malicious code in app-kst-engine (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (08cfc426d2f4b29bba2b81f2eb56eeee32ab114338a51fae5eeced2571e6b2d9)\nOn npm install, package.json's postinstall runs `node test.js`, which triggers three malicious paths against the installer. (1) A recursive scan of the current working directory collects files matching id.json, config.toml, Config.toml, env, and.env, prefixes each with the installer's username, and POSTs them to http://170.205.31.203:3000/api/v1. (2) Scan patterns are fetched from http://170.205.31.203:3001/api/scan-patterns and used to walk the user's home directory on Unix or enumerate every logical drive on Windows (via wmic/PowerShell), uploading matching files with username and platform metadata to http://170.205.31.203:3001/api/v1. (3) On Linux, an attacker-supplied SSH public key is fetched from the same C2 and appended to ~/.ssh/authorized_keys with mode 0o600, then `sudo ufw allow 22/tcp` is invoked to open the firewall, granting persistent remote SSH access. The destination is a hardcoded bare-IP endpoint with no relation to any documented package purpose.\n","affected":[{"package":{"ecosystem":"npm","name":"app-kst-engine"},"versions":["2.1.6"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"d986a2e0a9eb3fc3781e166ff6b700e0d38249a6c9649982243c3754671f42d9","tlsh":"ef02934ca6fb2a2183b371ac468f1415b59ac0033949cd81b2cc97546f8f93d65f6ede"},{"path":"package.json","sha256":"8296bee9db2ba7b59b3078e94f24e8a38f4a61d7f631e390180c3c2553709ff9","tlsh":"b9f0ed27ca588e6318f176a868bc0617f681932f4100880f35bd274c4fb61330089f1e"}],"package_integrity":[{"filename":"app-kst-engine-2.1.6.tgz","hashes":{"sha1":"306b98eaa8833598d7ad27bebfb2e40bb543e692","sha512_sri":"sha512-m63B/uKfUcmCNsvj1RWr5FcZui+XLwtWEydPH5ojn3S0yqKmJnn+xEDK5Pzt1zOjnumilSfsKT0I8Mvk1MLYzg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/app-kst-engine/v/2.1.6"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-015831","import_time":"2026-08-05T18:07:50.471941577Z","modified_time":"2026-08-05T17:22:35Z","sha256":"08cfc426d2f4b29bba2b81f2eb56eeee32ab114338a51fae5eeced2571e6b2d9","source":"amazon-inspector","versions":["2.1.6"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0