MAL-2026-13434Malicious code in @lyxa.ai/core (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @lyxa.ai/core | 1.0.129 |
| npm | @lyxa.ai/core | 1.0.13 |
| npm | @lyxa.ai/core | 1.0.144-test |
| npm | @lyxa.ai/core | 1.0.145-debug |
| npm | @lyxa.ai/core | 1.0.16 |
| npm | @lyxa.ai/core | 1.0.162-test |
| npm | @lyxa.ai/core | 1.0.201 |
| npm | @lyxa.ai/core | 1.0.206 |
| npm | @lyxa.ai/core | 1.0.23 |
| npm | @lyxa.ai/core | 1.0.281 |
| npm | @lyxa.ai/core | 1.0.333 |
| npm | @lyxa.ai/core | 1.0.37 |
| npm | @lyxa.ai/core | 1.0.386 |
| npm | @lyxa.ai/core | 1.0.56 |
| npm | @lyxa.ai/core | 1.0.79 |
| npm | @lyxa.ai/core | 1.0.8-debug-1 |
| npm | @lyxa.ai/core | 1.1.36 |
| npm | @lyxa.ai/core | 1.1.47 |
| npm | @lyxa.ai/core | 1.2.24 |
| npm | @lyxa.ai/core | 1.2.43 |
{"modified":"2026-08-06T23:29:17Z","published":"2026-08-06T16:50:14Z","schema_version":"1.7.4","id":"MAL-2026-13434","summary":"Malicious code in @lyxa.ai/core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1a32d4762c92b12ad7fd0567dfa0f07470a01884303acdc7a3585bfb4ad7fff2)\nThe exported bootstrapCore() unconditionally initializes the event bus with a hardcoded amqps:// URL containing embedded credentials for the author's CloudAMQP broker at dog.lmq.cloudamqp.com/vgyuplrd, with no override parameter. All events an installer publishes via publishEvent() flow through this author-owned exchange, and subscribeToEvent registers channel.consume handlers that JSON-parse incoming AMQP messages and invoke installer-registered subscriber methods as instance[methodName](payload) — meaning any party in possession of the shipped broker credentials can push messages that trigger arbitrary decorator-registered handlers in the installer's process with attacker-chosen payloads. ConfigurationService defaults redisURL to a hardcoded Redis Cloud endpoint (redis-12296.fcrce173.eu-west-1-1.ec2.redns.redis-cloud.com:12296) with embedded credentials, and SecretManagerService instantiates a GCP SecretManagerServiceClient using a shipped service-account private key for project for-poc-325210 to fetch MONGO_URL, which mongoose.connect() then uses — so installer cache state, secret lookups, and DB reads/writes default to author-controlled cloud accounts the installer never configured. The compiled bundle additionally ships a live GCP service-account private key (lyxa-core@for-poc-325210.iam.gserviceaccount.com), three Firebase Admin private keys (projects for-poc-325210, lyxa-rider-88939, lyxa-shop), a Redis Cloud password, and the CloudAMQP credentials, giving any third party administrative access to the same author-owned backends that installers of this package transitively depend on.\n","affected":[{"package":{"ecosystem":"npm","name":"@lyxa.ai/core"},"versions":["1.0.145-debug","1.0.144-test","1.0.16","1.0.8-debug-1","1.1.36","1.1.47","1.0.201","1.2.24","1.0.206","1.0.386","1.0.23","1.2.43","1.0.56","1.0.281","1.0.13","1.0.333","1.0.79","1.0.37","1.0.129","1.0.162-test"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"a63d36c32da581d44ce579798426ded1ed01ce9c2989aa65427fedea6011d9a0","tlsh":"12d122513bf794b2e137118a5b5b100b187bdb83b589f410b7fca326cfd35198297296"},{"path":"libraries/event/index.js","sha256":"4f1b649d25540fde69427e3b851ba6d507fa16edb89295b0b2b3aeb11ce2c86b","tlsh":"dd41314d39fa1971463b30ae472b9842113db5dfb901dc54b7dcde618fe4844da92f90"}],"package_integrity":[{"filename":"core-1.0.145-debug.tgz","hashes":{"sha1":"4ad3413f4e2ff858e3a1d5d1a39c4cc52628402a","sha512_sri":"sha512-+4n8tWB7hGiBoufbPsF3+A1e9qf2goWW8ovM7IKmYGYjZmdwh9VX5f5ro9EudOz10Qj4rfz0zCxwieAaQ55iEg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.145-debug"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.144-test"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.16"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.8-debug-1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.1.36"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.1.47"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.201"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.2.24"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.206"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.386"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.23"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.2.43"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.56"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.281"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.13"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.333"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.79"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.37"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.129"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@lyxa.ai/core/v/1.0.162-test"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016721","import_time":"2026-08-06T18:09:11.003923525Z","modified_time":"2026-08-06T16:50:22Z","sha256":"0aab606a35cc885f17daa4b943ffbc1ee3e691adfffa24513e5741758090953e","source":"amazon-inspector","versions":["1.0.145-debug"]},{"id":"IN-MAL-2026-016725","import_time":"2026-08-06T18:09:11.491293923Z","modified_time":"2026-08-06T16:51:03Z","sha256":"28e9b605fd0af18680342f725e028fc612744a47e2ddf6dc86b4352babc60bde","source":"amazon-inspector","versions":["1.0.144-test"]},{"id":"IN-MAL-2026-016727","import_time":"2026-08-06T18:09:11.758606421Z","modified_time":"2026-08-06T16:51:25Z","sha256":"9bc2087e4e8aefbb672176906a2c4024a3deb2b6b4114dcd2d75c5d222558588","source":"amazon-inspector","versions":["1.0.16"]},{"id":"IN-MAL-2026-016735","import_time":"2026-08-06T18:09:12.783949264Z","modified_time":"2026-08-06T16:52:44Z","sha256":"e8f074d2f617feee28f5f09f393dd6810df53a03b48cd23111239972d4dc6f7c","source":"amazon-inspector","versions":["1.0.8-debug-1"]},{"id":"IN-MAL-2026-016737","import_time":"2026-08-06T18:09:13.026656092Z","modified_time":"2026-08-06T16:53:03Z","sha256":"f9322cb3d37df8cb254835171dd2d48cee1076ae99e09344db7faa6c8ae15212","source":"amazon-inspector","versions":["1.1.36"]},{"id":"IN-MAL-2026-016736","import_time":"2026-08-06T18:09:12.901056584Z","modified_time":"2026-08-06T16:52:55Z","sha256":"c120262f3806a610de489ebcba7302780d2de23d17a488f5f234e4a7f3e13d65","source":"amazon-inspector","versions":["1.1.47"]},{"id":"IN-MAL-2026-016728","import_time":"2026-08-06T18:09:11.919177255Z","modified_time":"2026-08-06T16:51:36Z","sha256":"d4092c78614b93ae58f52ffada20d6d58314406edb72d0629e991148a6d0c8e4","source":"amazon-inspector","versions":["1.0.201"]},{"id":"IN-MAL-2026-016723","import_time":"2026-08-06T18:09:11.21947683Z","modified_time":"2026-08-06T16:50:41Z","sha256":"e4814f0506585fa3e90397e31051bcf2f7eb91f431f546f199b3ffe9afb51bc5","source":"amazon-inspector","versions":["1.2.24"]},{"id":"IN-MAL-2026-016731","import_time":"2026-08-06T18:09:12.267990588Z","modified_time":"2026-08-06T16:52:04Z","sha256":"9cafacec65b89c0bcfb7e67a3ddc0343a810ebebefec2b351341920e403545e9","source":"amazon-inspector","versions":["1.0.206"]},{"id":"IN-MAL-2026-016720","import_time":"2026-08-06T18:09:10.818619466Z","modified_time":"2026-08-06T16:50:14Z","sha256":"a25f0470927b0a29c20475fea96ba8ae11cc06b574aefea78b7359f2aca853ad","source":"amazon-inspector","versions":["1.0.386"]},{"id":"IN-MAL-2026-016733","import_time":"2026-08-06T18:09:12.564295904Z","modified_time":"2026-08-06T16:52:22Z","sha256":"d28aa236c1d0ad9141c90c5da56e1e7d859f64f6ad51b03fbe20de29606fba46","source":"amazon-inspector","versions":["1.0.23"]},{"id":"IN-MAL-2026-016726","import_time":"2026-08-06T18:09:11.61875495Z","modified_time":"2026-08-06T16:51:14Z","sha256":"311248c420ae79e6397bb7961b4f2ab734a76815214cfe411b81ec28f95e9b3b","source":"amazon-inspector","versions":["1.2.43"]},{"id":"IN-MAL-2026-016739","import_time":"2026-08-06T18:09:13.253792022Z","modified_time":"2026-08-06T16:53:21Z","sha256":"481ff2b9d0a967572af464a2cfe585ab185912cff1f7c8eb1fa22195171199a1","source":"amazon-inspector","versions":["1.0.56"]},{"id":"IN-MAL-2026-016732","import_time":"2026-08-06T18:09:12.460752068Z","modified_time":"2026-08-06T16:52:12Z","sha256":"5cf1130fa5c4ab011358f55541cb7e6ef97d3c399f680d04313d143f6260daf4","source":"amazon-inspector","versions":["1.0.281"]},{"id":"IN-MAL-2026-016724","import_time":"2026-08-06T18:09:11.34369105Z","modified_time":"2026-08-06T16:50:52Z","sha256":"94e7260ac245ed2753d2bb1457953b3dc3051bea86e74ef0e8e8679866b5a99b","source":"amazon-inspector","versions":["1.0.13"]},{"id":"IN-MAL-2026-016734","import_time":"2026-08-06T18:09:12.668902698Z","modified_time":"2026-08-06T16:52:35Z","sha256":"d2ae7e523e4ec08064360c7641b197eb9a0edc4906da8d4a61c29e0772e52bb1","source":"amazon-inspector","versions":["1.0.333"]},{"id":"IN-MAL-2026-016722","import_time":"2026-08-06T18:09:11.114592811Z","modified_time":"2026-08-06T16:50:31Z","sha256":"8810fa7234da9bf5bfd19d413f0c4b4e4fb82f178764d46b5db7c02a5caddf9c","source":"amazon-inspector","versions":["1.0.79"]},{"id":"IN-MAL-2026-016738","import_time":"2026-08-06T18:09:13.142154077Z","modified_time":"2026-08-06T16:53:13Z","sha256":"cedab42884ee8af136243a5af2230c36e900eb0207fb2b47c6e4f25c10d4596d","source":"amazon-inspector","versions":["1.0.37"]},{"id":"IN-MAL-2026-016730","import_time":"2026-08-06T18:09:12.145993344Z","modified_time":"2026-08-06T16:51:55Z","sha256":"1a32d4762c92b12ad7fd0567dfa0f07470a01884303acdc7a3585bfb4ad7fff2","source":"amazon-inspector","versions":["1.0.129"]},{"id":"IN-MAL-2026-016729","import_time":"2026-08-06T18:09:12.041449766Z","modified_time":"2026-08-06T16:51:46Z","sha256":"204fa170dfe32f0b2ef2e9be591f64578fedc097fd163b66fdf28758c6598990","source":"amazon-inspector","versions":["1.0.162-test"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0