MAL-2026-14119Malicious code in bcc-design-icons (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
9999.0.0 | archived | — | — | VIP 下载 |
| Ecosystem | Package | Version |
|---|---|---|
| npm | bcc-design-icons | 9999.0.0 |
{"modified":"2026-08-18T04:46:52Z","published":"2026-08-18T04:46:52Z","schema_version":"1.7.4","id":"MAL-2026-14119","summary":"Malicious code in bcc-design-icons (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2)\nbcc-design-icons@9999.0.0 declares a postinstall script `node./notify.js` that runs automatically on `npm install`. The script performs an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc with query parameters containing `os.hostname()` and the package name. The 9999.0.0 version, absence of any icon-library functionality expected from the package name, and callback-to-bare-IP shape match a dependency-confusion attack that identifies internal/private installers to the operator. Hostname is host-identifying data exfiltrated to an attacker-controlled destination without any installer opt-in.\n","affected":[{"package":{"ecosystem":"npm","name":"bcc-design-icons"},"versions":["9999.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"notify.js","sha256":"11ce834d0ec3450f68125c12032da2dceec8375f5d6780f6ae45e236b75e0e67","tlsh":"80f02eed81f4915831f249c8b2674562f211c151b84bd6c1fbcd22612fd6c66c6f34e8"}],"package_integrity":[{"filename":"bcc-design-icons-9999.0.0.tgz","hashes":{"sha1":"63ddc15c1baf00aed847600529437a6dbcd7373d","sha512_sri":"sha512-PAKsS2JpNpTH7j2ixGl2C2aXS2uwhYqR89dDxkwSk7bUaI0TCAtf2YwHaXyd4bIfbINBvwzrICfMAsfUPeyIdA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bcc-design-icons/v/9999.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-017986","import_time":"2026-08-18T05:13:46.108240238Z","modified_time":"2026-08-18T04:46:52Z","sha256":"8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2","source":"amazon-inspector","versions":["9999.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0