MAL-2026-14471Malicious code in cat-embed-i18n-res (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | cat-embed-i18n-res | 1.0.0 |
{"modified":"2026-08-25T06:35:38Z","published":"2026-08-25T06:35:38Z","schema_version":"1.7.4","id":"MAL-2026-14471","summary":"Malicious code in cat-embed-i18n-res (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c612800e80bb36720e75741be9665ab6acbed58bcd5d51065fcedd1d990aaad0)\nThe package's only shipped content, strings.json, is presented as an i18n/translation resource bundle but its values are HTML/JavaScript XSS payloads rather than localized text. Multiple entries use `<img src=x onerror=...>` and `<svg onload=...>` handlers that invoke fetch() against the hardcoded endpoint https://notpismo.cloud/c, sending `document.domain` and `document.cookie` as query parameters. Any consumer application that renders these strings as HTML (the ordinary use of an i18n bundle in web UIs) will execute the injected script in the end-user's browser and transmit that user's session cookies and hosting domain to notpismo.cloud. The package name and framing as a translation resource are a cover for the payload; there is no legitimate localization content in the file.\n","affected":[{"package":{"ecosystem":"npm","name":"cat-embed-i18n-res"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"strings.json","sha256":"91812910e4c4ba2bfe5c89aa50624eba6123341d102fd528371f430693bbf9a9","tlsh":"28d02ebe72accaab408040e0b011bbf0ec10f81e6829b9e1ca0ebc419a00c22a805523"}],"package_integrity":[{"filename":"cat-embed-i18n-res-1.0.0.tgz","hashes":{"sha1":"3de4b41d39156c508e01177a3a4620e69ab19d4a","sha512_sri":"sha512-vLd12PDJIFw/5OQdv+c5Zssj7ysWyRkqqXkl5LVcb3KGW0Dmwh0hT7a7Kt63+tyzjCxOn7oSQxhNq29ImH7gqA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cat-embed-i18n-res/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018685","import_time":"2026-08-25T06:50:12.477800077Z","modified_time":"2026-08-25T06:35:38Z","sha256":"c612800e80bb36720e75741be9665ab6acbed58bcd5d51065fcedd1d990aaad0","source":"amazon-inspector","versions":["1.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0