MAL-2026-14424Malicious code in @medisend/webview-bridge (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
0.0.1-security-research | archived | — | — | VIP 下载 |
0.0.2-security-research | unavailable | — | — | — |
| Ecosystem | Package | Version |
|---|---|---|
| npm | @medisend/webview-bridge | 0.0.1-security-research |
| npm | @medisend/webview-bridge | 0.0.2-security-research |
{"schema_version":"1.7.4","id":"MAL-2026-14424","published":"2026-08-24T14:01:03Z","modified":"2026-08-25T02:33:38.529260418Z","summary":"Malicious code in @medisend/webview-bridge (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ddf4b396c306b8f8d090b929c265b8ae848c75e53b9750d6f68800a4deefe9a2)\npackage.json declares a postinstall lifecycle script that runs curl to https://webhook.site/74ed1be3-96d6-48c3-932b-6b1dbabaff97 with query parameters populated from $(whoami), $(hostname), $(pwd), $(ls -la), and $(node -v). On every npm install the installer's username, hostname, working directory, a directory listing of the install location, and Node.js version are sent to a third-party webhook.site collector controlled by whoever provisioned that endpoint. The package publishes under the @medisend scope and its description states a dependency-confusion test referencing a third-party VDP; an installer whose internal tooling resolves the public registry version instead of an internal @medisend package will trigger this exfiltration automatically.\n\n## Source: ossf-package-analysis (bcefced9c742cce25a3c42fdb4cd5c9f2545184e7b661fff98f362ba0a566ce1)\nThe OpenSSF Package Analysis project identified '@medisend/webview-bridge' @ 0.0.2-security-research (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","affected":[{"package":{"name":"@medisend/webview-bridge","ecosystem":"npm"},"versions":["0.0.1-security-research","0.0.2-security-research"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"c90e25369be90d0f07612c0ef7ff6fe8d31136dd138c0064ba942f8de4ef21e2","tlsh":"41e068b528a411360ae846fa0930a00dba36c60d710b2b0bc2da42e8a30d7f81713698"}],"package_integrity":[{"filename":"webview-bridge-0.0.1-security-research.tgz","hashes":{"sha1":"fc3b448ebf599b77a528cef9a5d6bbd589cd5614","sha512_sri":"sha512-EF5zp5a9ViGGjyMXElR6ChxxiMGUVodwgWvsP6WiumODwsFvyE2QFhOL0/cG2Wyo15q9ZqkP2WXPSV5Z9gSTCQ=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@medisend/webview-bridge/v/0.0.1-security-research"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@medisend/webview-bridge/v/0.0.2-security-research"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018655","import_time":"2026-08-24T16:49:15.341946611Z","modified_time":"2026-08-24T16:46:50Z","sha256":"3a3d83177c7024c8d0ba6794e89b12a41ac0e1d7b00543b7105b96f09a7b8039","source":"amazon-inspector","versions":["0.0.1-security-research"]},{"id":"IN-MAL-2026-018651","import_time":"2026-08-24T16:49:15.025338736Z","modified_time":"2026-08-24T16:46:11Z","sha256":"ddf4b396c306b8f8d090b929c265b8ae848c75e53b9750d6f68800a4deefe9a2","source":"amazon-inspector","versions":["0.0.2-security-research"]},{"import_time":"2026-08-25T02:31:33.274014458Z","modified_time":"2026-08-24T14:01:03Z","sha256":"bcefced9c742cce25a3c42fdb4cd5c9f2545184e7b661fff98f362ba0a566ce1","source":"ossf-package-analysis","versions":["0.0.2-security-research"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0