MAL-2026-14245Malicious code in github-policy-bot (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | github-policy-bot | 1.0.0 |
{"modified":"2026-08-19T03:52:07Z","published":"2026-08-19T03:52:07Z","schema_version":"1.7.4","id":"MAL-2026-14245","summary":"Malicious code in github-policy-bot (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (87b8742a99002975ebaced2478673108f4f442e5ac7878651edeb8346702f132)\nOn `npm install`, the package's postinstall script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded host vlfl47tl.instances.poc.jchunt.top at path /github-policy-bot. The outbound request is fail-silent (error handler swallows failures) and short-timeout, consistent with a beacon. The package name shadows the Google-owned `js-github-policy-bot` repository path referenced in the tarball's source.txt, and the package.json author is a placeholder (`r00tdaddy`) with a self-declared 'security research canary' purpose — an author-controlled label that does not change the behavior. Installing this package causes unsolicited disclosure of the installer's hostname and environment metadata to a third-party endpoint the installer did not configure.\n","affected":[{"package":{"ecosystem":"npm","name":"github-policy-bot"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"1f39c16726c49952d82a48aa38d599c6d664e1e9f372f1b8b3e092cdaa88787a","tlsh":"6b019ed5d2b5567557b8628068e1af0693baf2233b0660b669c445a92fcd1f5003219d"},{"path":"source.txt","sha256":"188cf8944f9888a9a790607b74b91eb1f69900e5253b6941ba4e9b8340230509","tlsh":"3eb022c22023c082cf0c2c3c088c0020b33b3008fca0a0f2c80a0f80e080cfc0a03308"}],"package_integrity":[{"filename":"github-policy-bot-1.0.0.tgz","hashes":{"sha1":"0a5672a6b1d53b30f81cb5a9eefb6cece349aae6","sha512_sri":"sha512-lbofepwkCdYTOfDmH4PnIjLWr8Pl4LwNBHfr0eJzQcSrgOKPq3ebFCcqjAd+tzcbYtd+vvgcnFm5FMs+Di3otQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/github-policy-bot/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018342","import_time":"2026-08-19T04:18:13.578421427Z","modified_time":"2026-08-19T03:52:07Z","sha256":"87b8742a99002975ebaced2478673108f4f442e5ac7878651edeb8346702f132","source":"amazon-inspector","versions":["1.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0