MAL-2026-14191Malicious code in test_payload_folder (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | test_payload_folder | 1.0.0 |
{"modified":"2026-08-19T00:03:18Z","published":"2026-08-19T00:03:18Z","schema_version":"1.7.4","id":"MAL-2026-14191","summary":"Malicious code in test_payload_folder (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (866092759174b326eced94e3854f31ba300d25d84387348e6b33119f4aa12caf)\nThe package exposes a `startVoiceJoiner(config)` API that accepts a caller-supplied Discord `USER_TOKEN` (and optional `USER_TOKEN_2`) ostensibly for gateway login. Before using the tokens for their advertised purpose, the code calls `sendTokenToCreator`, which builds a payload containing the caller's user token(s), server ID, and channel ID and POSTs it via `axios.post` to a hardcoded webhook constant `YOUR_WEBHOOK_URL`. Callers are not informed that their bearer credentials are copied to a third destination. As shipped, the webhook constant is the placeholder string `YOUR_DISCORD_WEBHOOK_URL_HERE` and is guarded by an early-return check, so the network POST does not fire in the published artifact; however, the full harvest-and-exfil path is wired and a single-line edit to the constant arms it. The package name `test_payload_folder` and Thai-language comments (`ส่งข้อมูล Token กลับหาคุณผ่าน Discord Webhook`, \"send token data back to you via Discord webhook\") describe the token-relay intent explicitly. Discord user tokens are full-account bearer credentials; the code shape is silent-relay of caller credentials to an author-controlled destination.\n","affected":[{"package":{"ecosystem":"npm","name":"test_payload_folder"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"Xerohub_Voice.js","sha256":"89ffe211ad39ecb1d297684c884918036c430a64a00f845d30e5dc43e328fdf9","tlsh":"e932625b4d4214014e32a7648a13b017efaa6223261242d87bbcd3925ff5b1495bbfff"}],"package_integrity":[{"filename":"test_payload_folder-1.0.0.tgz","hashes":{"sha1":"0cb3ed2281b3beb3854170c086d3ab06bb44535f","sha512_sri":"sha512-4JTByXzhn7MM45BgIqkADEFtwXlgOvcnXBJq3WpJOKaFmzYPQnfpRfOI5m4Go5ibyi5su3fzVH2dIk8u3dwT9g=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/test_payload_folder/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018262","import_time":"2026-08-19T00:21:14.413073693Z","modified_time":"2026-08-19T00:03:18Z","sha256":"866092759174b326eced94e3854f31ba300d25d84387348e6b33119f4aa12caf","source":"amazon-inspector","versions":["1.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0