MAL-2026-14432Malicious code in kelly-stake-sizing (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | kelly-stake-sizing | 0.1.1 |
{"modified":"2026-08-24T16:46:01Z","published":"2026-08-24T16:46:01Z","schema_version":"1.7.4","id":"MAL-2026-14432","summary":"Malicious code in kelly-stake-sizing (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6ca23e704ca44d185fc873044a3a967e06d996970f59a526d3390e1f0ab45a9d)\nkelly-stake-sizing@0.1.1 declares postinstall = 'node scripts/install-check.cjs'. That script fetches a JSON config from https://pm-trading-tool-be.vercel.app/config/clob-math.json, resolves a bundle URL from it, downloads a.tgz to a temp path, extracts it, runs 'npm install --omit=dev --no-audit --no-fund' inside the extracted directory, then require()s peer-math.js from the extracted bundle and invokes syncSession(). The fetched code is not shipped in the tarball, is not version-pinned, and is not hash- or signature-verified; the JSON config the URL is derived from is author-mutable. As a result, installing this package causes arbitrary attacker-controlled JavaScript, plus any transitive npm dependencies (and their own lifecycle scripts) declared in the remote bundle, to execute at install time with the privileges of the npm install process.\n","affected":[{"package":{"ecosystem":"npm","name":"kelly-stake-sizing"},"versions":["0.1.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"scripts/install-check.cjs","sha256":"3e15f1692c4075cf29cefa94c84d564a95086ab7a6838a97ea25cd02475a282d","tlsh":"6ad1659915a272770bb0e7a4cb53a41eeb6394233511c364f6cdc6952ff6164c213dec"}],"package_integrity":[{"filename":"kelly-stake-sizing-0.1.1.tgz","hashes":{"sha1":"6cd24cbeb9cb6f71c569ace4853a7385079faed5","sha512_sri":"sha512-ikggeggEJTC37Nq8PyaVGKUMBCB8NQQ6SBbYLJ1Nuu3dcHEtMRVFo5d4Usklmduh29xKsnQJ4peb5g1BCqMS2Q=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/kelly-stake-sizing/v/0.1.1"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018650","import_time":"2026-08-24T16:49:14.960133789Z","modified_time":"2026-08-24T16:46:01Z","sha256":"6ca23e704ca44d185fc873044a3a967e06d996970f59a526d3390e1f0ab45a9d","source":"amazon-inspector","versions":["0.1.1"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0