MAL-2026-14373Malicious code in hatdhat-testkit (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | hatdhat-testkit | 3.2.14 |
{"modified":"2026-08-23T03:14:11Z","published":"2026-08-23T03:14:11Z","schema_version":"1.7.4","id":"MAL-2026-14373","summary":"Malicious code in hatdhat-testkit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (83b6e58e31221d5d14386a193ab49381950bb01307ac4fb4d7e5c30d246046d9)\nPackage presents itself as a pino-style logging utility but its middleware entrypoint (index.js) spawns lib/caller.js as a detached Node process. caller.js contains a fake `process` object whose `env.DEV_API_KEY`, `env.DEV_SECRET_KEY`, and `env.DEV_SECRET_VALUE` are base64 strings that decode to the URL https://api.jsonstorage.net/v1/json/2ef8c758-a96f-459e-b036-b3b90379a165/f89e8264-86c2-4684-94da-c3f82d59370f, the request header name `x-secret-key`, and its value. The loader GETs that mutable anonymous JSON blob and executes the response's `cookie` field via `new Function.constructor('require', s)(require)` with retry, granting the remote payload full Node capabilities including require(). The destination is unrelated to the advertised logging purpose and the URL/header are obfuscated to evade inspection.\n","affected":[{"package":{"ecosystem":"npm","name":"hatdhat-testkit"},"versions":["3.2.14"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"lib/caller.js","sha256":"ffa61701ff61ebc0c6d64cf09f5bc37a74a91b03b716129b90271d758dc164b7","tlsh":"6e01efd934fd501c021111ea171fa032a010e4373882d6c8374cc7428fa66bd2e93aef"}],"package_integrity":[{"filename":"hatdhat-testkit-3.2.14.tgz","hashes":{"sha1":"176d8ef955273ca1b7b04ac7930c75dd4170766d","sha512_sri":"sha512-onOtdYMlIyxoAiTT6+pHBwn78GGgqCfrhIBB6rIzEegiVWE5JTdImMAS9tL+JCgUWHbq/J4qq3nuBTficBCEwA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/hatdhat-testkit/v/3.2.14"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018566","import_time":"2026-08-23T03:25:55.914232386Z","modified_time":"2026-08-23T03:14:11Z","sha256":"83b6e58e31221d5d14386a193ab49381950bb01307ac4fb4d7e5c30d246046d9","source":"amazon-inspector","versions":["3.2.14"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0