MAL-2026-13690Malicious code in @noobaihome/amis-uni-area-widget (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @noobaihome/amis-uni-area-widget | 1.0.0 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.1 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.10 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.11 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.2 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.4 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.5 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.6 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.7 |
| npm | @noobaihome/amis-uni-area-widget | 1.0.8 |
{"modified":"2026-08-10T12:26:44Z","published":"2026-08-10T11:54:13Z","schema_version":"1.7.4","id":"MAL-2026-13690","summary":"Malicious code in @noobaihome/amis-uni-area-widget (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561)\nscripts/install.js runs during npm preinstall and performs three attacker-beneficial actions against the installer host. First, it unconditionally beacons installer identifiers (pid, base64-encoded process.cwd(), base64-encoded process.env.INIT_CWD, and a marker) over plain HTTP to the hardcoded bare-IP endpoint http://49.232.169.67:43817/bsrc-r260. Second, when a parent build manifest matches an internal marker, it downloads a shell script from http://49.232.169.67:80/slt via curl (with a wget fallback) and pipes the response into /bin/sh through spawnSync, giving the remote host arbitrary code execution on the installer at install time. Third, it fetches http://bsrc-ssrf.n.baidu-int.com/bsrc_uid — an internal-network endpoint reachable only from inside a specific corporate network — and forwards the base64-encoded response body back to the same 49.232.169.67:43817 callback, characteristic of an SSRF-driven internal reconnaissance probe. The destination is a bare IPv4 address on plain HTTP with no relationship to any documented publisher, the fetched shell script is unpinned and unverified, and all three behaviors fire automatically on npm install.\n","affected":[{"package":{"ecosystem":"npm","name":"@noobaihome/amis-uni-area-widget"},"versions":["1.0.7","1.0.8","1.0.11","1.0.1","1.0.4","1.0.6","1.0.0","1.0.2","1.0.5","1.0.10"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"dist/bsrc-loader.js","sha256":"7c2ddfe2a4d569f1059d7d5de6a8e7f220a5fdf8b37b14a1b0b688557ccd8dcd","tlsh":"6171976729f728669b53d0d8a21b4826b61281433997c9f4b94c03942fc7074d573afd"}],"package_integrity":[{"filename":"amis-uni-area-widget-1.0.7.tgz","hashes":{"sha1":"35ced38edc44097413f104270a7ecafaa039c952","sha512_sri":"sha512-TDaYSBk06aimZebC/5I5kdQ6QrisSYxtfL9wstNy19pl++cO9sdEbVIw330AuoLlZyaIo3wKGF6cCYoqSQFSgw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.7"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.11"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.6"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@noobaihome/amis-uni-area-widget/v/1.0.10"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017240","import_time":"2026-08-10T12:24:45.518303263Z","modified_time":"2026-08-10T11:55:16Z","sha256":"15510a6c21ecdd743474138e5ce36700a133705b31ab4e9d1651d298feaf66f8","source":"amazon-inspector","versions":["1.0.7"]},{"id":"IN-MAL-2026-017242","import_time":"2026-08-10T12:24:45.730864322Z","modified_time":"2026-08-10T11:55:33Z","sha256":"2518f3a152632cdb5e9fe503102eb09f8ba7b79a6b8ea5f9ecc193206a8c2b6b","source":"amazon-inspector","versions":["1.0.8"]},{"id":"IN-MAL-2026-017238","import_time":"2026-08-10T12:24:45.280902346Z","modified_time":"2026-08-10T11:54:58Z","sha256":"517ad8810b4a12e80381570f0ec88b7b708d810c97a2a90711ae68172c9af51a","source":"amazon-inspector","versions":["1.0.11"]},{"id":"IN-MAL-2026-017241","import_time":"2026-08-10T12:24:45.638971752Z","modified_time":"2026-08-10T11:55:26Z","sha256":"87b5f72e01a3ae3eabab4af272133f2a3536a47aa2444b8b810a241ac6ef8b09","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017243","import_time":"2026-08-10T12:24:45.883181069Z","modified_time":"2026-08-10T11:55:42Z","sha256":"9dc6a9f3ec560cd4e83b7682e81c6349aa184892de353e807c41b3576a59a743","source":"amazon-inspector","versions":["1.0.4"]},{"id":"IN-MAL-2026-017239","import_time":"2026-08-10T12:24:45.412722281Z","modified_time":"2026-08-10T11:55:07Z","sha256":"c5d7fdcc7c80d935460b3c3080915e805c96d6ea904593786afd9d985439a511","source":"amazon-inspector","versions":["1.0.6"]},{"id":"IN-MAL-2026-017233","import_time":"2026-08-10T12:24:44.812053977Z","modified_time":"2026-08-10T11:54:13Z","sha256":"ca5d69656e3a385d08858223b6c6ca2abbef7896020921f5319f874dd39588e4","source":"amazon-inspector","versions":["1.0.0"]},{"id":"IN-MAL-2026-017236","import_time":"2026-08-10T12:24:45.087805026Z","modified_time":"2026-08-10T11:54:41Z","sha256":"1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561","source":"amazon-inspector","versions":["1.0.2"]},{"id":"IN-MAL-2026-017237","import_time":"2026-08-10T12:24:45.182843879Z","modified_time":"2026-08-10T11:54:51Z","sha256":"9e842cae97f83fd281bc9949bf01908a87bd08d885cef712d2dd7c021601939e","source":"amazon-inspector","versions":["1.0.5"]},{"id":"IN-MAL-2026-017235","import_time":"2026-08-10T12:24:45.003788111Z","modified_time":"2026-08-10T11:54:29Z","sha256":"d055000a3d6bd5333d0c4edc67a78f31703a56f2766fec9227a7c611ddae3a55","source":"amazon-inspector","versions":["1.0.10"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0