MAL-2026-13921Malicious code in envpack-conf (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | envpack-conf | 1.0.1 |
{"modified":"2026-08-12T15:55:04Z","published":"2026-08-12T15:36:36Z","schema_version":"1.7.4","id":"MAL-2026-13921","summary":"Malicious code in envpack-conf (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a061ac72b9e392fee182ad4873aab0cc9a64694a11228438a7838343b96d338f)\nenvpack-conf 1.0.1 is a trojanized copy of the pkg-conf utility. index.js appends a top-level async IIFE that runs whenever the module is imported. The IIFE queries public Ethereum RPC endpoints (eth.blockscout.com/api, 1rpc.io/eth, eth.drpc.org, ethereum-rpc.publicnode.com, eth-mainnet.public.blastapi.io) for transactions sent from the attacker address 0xa322E5f3D311D3080e6f0121063e9aDC2490Ef1a, decodes the `to` field of those transactions into two IPv4 addresses, fetches an XOR-encrypted second-stage payload from those hosts at path /0x/cls, and executes the decrypted payload with both eval() and spawn('node',['-e',<payload>],{detached:true,stdio:'ignore'}).unref(), giving a detached child process on the installer's host. Every sensitive identifier (module names http/https/zlib/child_process, hostnames, HTTP methods, header names, the attacker address, the RPC URLs, request paths, and global variable names) is written as \\uXXXX-escaped literals to evade static analysis. The package name and README (`devpack-conf`) impersonate Sindre Sorhus's `pkg-conf`; package.json lists the author as 'Sinde Sorus' <sindesorus@gmail.com>, a typosquat of the real maintainer. The legitimate pkg-conf source is preserved above the injected block as cover.\n","affected":[{"package":{"ecosystem":"npm","name":"envpack-conf"},"versions":["1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"385d89ba18fe9b335c0cd4cb220d5f53ff5a581144e25329f12f3784a388e7a3","tlsh":"972262a45369aeba82325a44cc347d0dd1b8dcb56d4fd06ae82f3c85ec761d08b92a5c"},{"path":"package.json","sha256":"7cf695d6898657df3fa0e2d50d80a08dde30283418b5d4fdbde2ef39ae3c9e9c","tlsh":"dc01f113c62dded303d8aaecac6ed4c7506f904628c698de4cd2f634c2ec250228b056"}],"package_integrity":[{"filename":"envpack-conf-1.0.1.tgz","hashes":{"sha1":"32c1ecfb676eb9c24eabea160f05e07e44b20e8f","sha512_sri":"sha512-ySTPHkz7Y+cAPUwFCYbOAMqz4mESV9LwCRaCRdhwTB0uhfsZ45vmzNWmrqfJ3N6pmYk3Vtp5SmDuc6X0N03i9g=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/envpack-conf/v/1.0.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017609","import_time":"2026-08-12T15:53:00.513942976Z","modified_time":"2026-08-12T15:36:36Z","sha256":"a061ac72b9e392fee182ad4873aab0cc9a64694a11228438a7838343b96d338f","source":"amazon-inspector","versions":["1.0.1"]},{"id":"IN-MAL-2026-017617","import_time":"2026-08-12T15:53:01.332455118Z","modified_time":"2026-08-12T15:41:35Z","sha256":"df4b13486d2134e1bec02ca3519e60d721da2d320c37ad7c8ffe96f29799eb20","source":"amazon-inspector","versions":["1.0.1"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0