MAL-2026-13429Malicious code in @avi892nash/aegis-grid-runner (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @avi892nash/aegis-grid-runner | 0.3.3 |
{"modified":"2026-08-06T15:48:23Z","published":"2026-08-06T15:48:23Z","schema_version":"1.7.4","id":"MAL-2026-13429","summary":"Malicious code in @avi892nash/aegis-grid-runner (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d81514bec2b648731e0db3b59e1adbd308a5b099f80af8be6caac5db71103a00)\nThe package's default `bin` action starts an HTTP server (grid.mjs) that listens on GRID_RUNNER_PORT (default 7719). Incoming requests carry a base64-JSON `x-job-meta` header containing a `cmd` string plus a gzipped code tarball; the runner decodes the header, extracts the tarball, and invokes `child_process.spawn` on `meta.cmd` in a shell on the host running the runner. The runner boots unpaired by default and accepts pairing via `POST /api/master`; token authentication (GRID_TOKEN) is optional per README, so a peer able to reach the port can pair and drive arbitrary shell command execution on the host. The bundle also contains references to internal Juspay infrastructure (`ssh://git@ssh.bitbucket.juspay.net/picaf/aegis.git`) and internal LAN addresses (192.168.0.50:7719, 192.168.0.146:7717) used as example onboarding strings, indicating an internal tool published to the public registry.\n","affected":[{"package":{"ecosystem":"npm","name":"@avi892nash/aegis-grid-runner"},"versions":["0.3.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"grid.mjs","sha256":"0bd05b67367efa834c19d728c90fa6ad858941f44403e6b9fd99c8d8c4d29b6b","tlsh":"4064f74151f62037473350ad1ecb615eb6ea88077d46c870fadcf2583fc7924a6b7aa8"}],"package_integrity":[{"filename":"aegis-grid-runner-0.3.3.tgz","hashes":{"sha1":"51091cf09eb0e332044127e31cf0b42f5c491476","sha512_sri":"sha512-gKLZvggl+zy5lsCAGObbDX4FvA/GzDB7OmZSMgl5CzajABWNB+D9blVqr4YqHfM+TOTXz2Q9wgL/M3oz4+t9rg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@avi892nash/aegis-grid-runner/v/0.3.3"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016660","import_time":"2026-08-06T18:09:02.593452079Z","modified_time":"2026-08-06T15:48:23Z","sha256":"d81514bec2b648731e0db3b59e1adbd308a5b099f80af8be6caac5db71103a00","source":"amazon-inspector","versions":["0.3.3"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0