MAL-2025-49456

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/0e/MAL-2025-49456.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2025-49456
Published
2025-11-09T16:46:21Z
Modified
2026-05-13T20:23:24.985722Z
Summary
Malicious code in 0e (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (71d3f3352259e4eb03352ae7be99bea6511ba3092aeb42a62c5ede4fb82dd614)

a static rule a static pattern match (critical) flagged index.js for containing a Telegram bot token, chat_id, sendMessage endpoint, a console Proxy wrapper, and JSON.stringify — the canonical shape of a console-exfiltration stealer, matching the credential-regex-fingerprints pattern. The analysis found that hardcoded imgbb API key, Telegram bot token, hardcoded chat IDs, and Firebase realtime-DB writes, with a Proxy installed over the global console that ships log arguments to attacker-controlled Telegram and Firebase endpoints. While the analysis downgraded this to 'info' because index.js is not the declared main and is purportedly syntactically broken, shipping a weaponized exfiltration module inside an npm tarball is itself a supply-chain threat: (a) any downstream consumer or tool that imports by path would be exposed if the syntax issue is fixed or if only part of the file is consumed, (b) the presence of a working Telegram token + chat id + Firebase endpoint indicates deliberate malicious intent, not accident. Additionally, shows the actual entrypoint test.js performs an import-time HTTPS ESM self-import from cdn.skypack.dev and an unconditional fetch to a Cloudinary URL, which is unusual load-time network activity for a package with no described purpose. Combined signals: placeholder/meaningless package (name '0e'), import-time remote fetch in entrypoint, and a bundled credential-exfiltration module — consistent with an attacker-staged package rather than a benign library.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2025-11-09T17:05:39.471947354Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "source": "amazon-inspector",
            "sha256": "07176e4dc8520fb6b74efee8c500942a2c30b2b4f6bbe37229fd704bbe3558d6",
            "modified_time": "2025-11-09T16:46:21Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.227204525Z",
            "source": "amazon-inspector",
            "sha256": "c038934c80f2dd380576dfa2d1573e429384b900ac1182ec52b03229ea5cce91",
            "versions": [
                "0.0.103"
            ],
            "id": "IN-MAL-2026-002294",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.28028765Z",
            "source": "amazon-inspector",
            "sha256": "3e250dc53095368050d1212297ce415a819c00d7a4e367be4fb47ec051e92611",
            "versions": [
                "0.0.16"
            ],
            "id": "IN-MAL-2026-002307",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.545905792Z",
            "source": "amazon-inspector",
            "sha256": "80a05c0609a9ffcc8872fd2634c2d262824786f666fdc756cdb7c085da1c7d1f",
            "versions": [
                "0.0.191"
            ],
            "id": "IN-MAL-2026-002311",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.720717733Z",
            "source": "amazon-inspector",
            "sha256": "b60c79c91f33c449d5afd4dbe8f5712f81ee3762b989bec1c7789efa84b7829f",
            "versions": [
                "0.0.108"
            ],
            "id": "IN-MAL-2026-002300",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.664173152Z",
            "source": "amazon-inspector",
            "sha256": "fcb9a8f207cbfae919fcf06758eb910d26fa9367586c0fe18ec98026c2d33107",
            "versions": [
                "0.0.193"
            ],
            "id": "IN-MAL-2026-002313",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.906748422Z",
            "source": "amazon-inspector",
            "sha256": "0a343d3b6275e05c2864cc78b0fd1e7feb947718e6f4c53233ed7ad470e2f4a9",
            "versions": [
                "0.0.12"
            ],
            "id": "IN-MAL-2026-002303",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.998307087Z",
            "source": "amazon-inspector",
            "sha256": "72767b756b6c21cd0f264d0384a1373abab4edb9c5f3f9d829b8f66ace096645",
            "versions": [
                "0.0.13"
            ],
            "id": "IN-MAL-2026-002304",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.468636884Z",
            "source": "amazon-inspector",
            "sha256": "b5e44cb01737753c426f0c9019b8f60271d223d1dd03764d93c454c4d1c54372",
            "versions": [
                "0.0.106"
            ],
            "id": "IN-MAL-2026-002297",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.187540585Z",
            "source": "amazon-inspector",
            "sha256": "e17a41017f7d8c892e796597ea42123c77f44f4c86dff2487dbec5b5c76d0c07",
            "versions": [
                "0.0.1"
            ],
            "id": "IN-MAL-2026-002293",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.423206082Z",
            "source": "amazon-inspector",
            "sha256": "ef3b365ae0b69a2ec0124d0ceac49683194d151740e75aab104ce23a0967495e",
            "versions": [
                "0.0.18"
            ],
            "id": "IN-MAL-2026-002309",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.072737205Z",
            "source": "amazon-inspector",
            "sha256": "71d3f3352259e4eb03352ae7be99bea6511ba3092aeb42a62c5ede4fb82dd614",
            "versions": [
                "0.0.14"
            ],
            "id": "IN-MAL-2026-002305",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.157363346Z",
            "source": "amazon-inspector",
            "sha256": "a99aac685074b5278c4d0ebf8fa78bd2558c0bfa7eb5e0291c14fe44e2771f7d",
            "versions": [
                "0.0.15"
            ],
            "id": "IN-MAL-2026-002306",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.470001951Z",
            "source": "amazon-inspector",
            "sha256": "af0a2e2b9450a4378511235b34796ebbc013b57c84eef47a9496e982de74bdd6",
            "versions": [
                "0.0.19"
            ],
            "id": "IN-MAL-2026-002310",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.292610449Z",
            "source": "amazon-inspector",
            "sha256": "c5c99fe5fb4ccd835b2db3c31d49a20e333da211bbea2a9f031b4da4e86e522a",
            "versions": [
                "0.0.104"
            ],
            "id": "IN-MAL-2026-002295",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.789574601Z",
            "source": "amazon-inspector",
            "sha256": "ddfbb95af78da86aea8e7650c3c85656c6b22572a90cf3b4d809b1f1d54336cd",
            "versions": [
                "0.0.109"
            ],
            "id": "IN-MAL-2026-002301",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.366755564Z",
            "source": "amazon-inspector",
            "sha256": "e1c58d110be5169ba90d2f1532559f4250a66258382fd298e3a16c5fad1ba6be",
            "versions": [
                "0.0.17"
            ],
            "id": "IN-MAL-2026-002308",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.859624972Z",
            "source": "amazon-inspector",
            "sha256": "e4ec242a5bfc40320d8e805a762a6dc80e0b3a9ea416c9cd40bbdfd177cbc593",
            "versions": [
                "0.0.11"
            ],
            "id": "IN-MAL-2026-002302",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.365894807Z",
            "source": "amazon-inspector",
            "sha256": "1d2acfae48418b85fd8c9531130c24217a0c46093767c746cf0ba34005e58864",
            "versions": [
                "0.0.105"
            ],
            "id": "IN-MAL-2026-002296",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:55.604149473Z",
            "source": "amazon-inspector",
            "sha256": "233f947b924b24f2101881464fbbf4a8ccefb3d5bdc02d4188d73e13ccbd342e",
            "versions": [
                "0.0.192"
            ],
            "id": "IN-MAL-2026-002312",
            "modified_time": "2026-05-12T19:03:07Z"
        },
        {
            "import_time": "2026-05-13T20:10:54.6358741Z",
            "source": "amazon-inspector",
            "sha256": "95179a5c838fc2c84bb6ac9d15f22a9e1607a735cf2334baaec83d197c770ef1",
            "versions": [
                "0.0.107"
            ],
            "id": "IN-MAL-2026-002299",
            "modified_time": "2026-05-12T19:03:07Z"
        }
    ]
}
References
Credits

Affected packages

npm / 0e

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.0.1
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.103
0.0.104
0.0.105
0.0.106
0.0.107
0.0.108
0.0.109
0.0.191
0.0.192
0.0.193

Database specific

indicators
{
    "evidence_files": [
        {
            "tlsh": "e83100575f4888312a76132d1e93f04ff0258b3b94a868b6bc9dd2f2df710e289d1d85",
            "sha256": "bbec68bd43af18372bb01d2748a350972cc433bb15d2f4c5c92715bfc4207992",
            "path": "src/6cc.js"
        },
        {
            "tlsh": "f0c08c3800629d2308d286e7ba8a66112ab6400e0100a202320f604c068a1b900de3fe",
            "sha256": "51b456455aa8b9c93c3ae17b6b29623442fa700e44f18539bd2f761b1ffd2a8f",
            "path": "index.js"
        }
    ],
    "domains": [
        "api.telegram.org",
        "iiilll.firebaseio.com"
    ],
    "package_integrity": [
        {
            "filename": "0e-0.0.103.tgz",
            "hashes": {
                "sha1": "c5478183e471fc8ad95a3bab4c2f109354712ce5",
                "sha512_sri": "sha512-VHV8PSuW4f3Emfn8vSDo4w6MBnN6qR2iz5JwVvPL/UHbd+355RoAeoDZOaxYZkRvFdHT7AN82cZIX/R8KswzYg=="
            }
        }
    ],
    "urls": [
        "https://api.telegram.org/bot${T}/sendMessage?chat_id=${chat}&text=${encodeURIComponent(l",
        "https://iiilll.firebaseio.com/${TT}.json"
    ]
}
cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/0e/MAL-2025-49456.json"