MAL-2026-10769

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/easyway2/MAL-2026-10769.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10769
Published
2026-07-17T12:44:58Z
Modified
2026-07-28T14:36:56Z
Summary
Malicious code in easyway2 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fcfc1bc035f5239e384f9e32be4fc53cdffe065920da7c6181e42757d6b41195)

On npm install, the package's postinstall hook executes index.js, which POSTs the installer's full process.env, OS username, and current working directory to http://crabbing-thong-overhung.ngrok-free.dev/v1/init over plain HTTP. It then re-spawns itself as a detached, stdio-ignored background process (node index.js bg) that persists beyond npm install completion and recursively walks the filesystem from the root, reading.env,.conf,.json,.yaml,.yml,.sql,.log,.txt,.js, and dotfiles. Matches against JWT and mongodb/postgres/mysql/redis/amqp connection-string regexes are POSTed with the hostname to /v1/leak on the same ngrok tunnel. The ngrok-free.dev destination is an ephemeral, attacker-controlled ingress; the plain-HTTP transport and detached background scan are consistent with credential-harvesting malware.

Source: ossf-package-analysis (b70fe150bb8d389d4b3f437dff96763448359cafed12db8139236f3d40b88565)

The OpenSSF Package Analysis project identified 'easyway2' @ 1.0.3 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-07-17T12:58:02.018368476Z",
            "modified_time": "2026-07-17T12:44:58Z",
            "sha256": "b70fe150bb8d389d4b3f437dff96763448359cafed12db8139236f3d40b88565",
            "source": "ossf-package-analysis",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "import_time": "2026-07-17T14:36:10.405326207Z",
            "modified_time": "2026-07-17T14:10:44Z",
            "sha256": "dff64fea0cd0fc61895597193439279782028def9d61a53fa870e90a4cfb7a50",
            "source": "ossf-package-analysis",
            "versions": [
                "1.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-010925",
            "import_time": "2026-07-28T14:19:59.342286115Z",
            "modified_time": "2026-07-28T13:37:17Z",
            "sha256": "2aed763a51b55d0830b211bb892f32531304b1f06b17109a8e82d5fba41d9c7a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.11"
            ]
        },
        {
            "id": "IN-MAL-2026-010930",
            "import_time": "2026-07-28T14:19:59.57556823Z",
            "modified_time": "2026-07-28T13:38:03Z",
            "sha256": "401380d5c2d7140f8776cbcc91a659162768719fcf84f8a4035072e5de59a9d6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-010910",
            "import_time": "2026-07-28T14:19:58.636907404Z",
            "modified_time": "2026-07-28T13:35:00Z",
            "sha256": "7f826eb21c09c1992cb7181e603af9580b86c45119c7e1c8be2f700897a97f52",
            "source": "amazon-inspector",
            "versions": [
                "1.0.8"
            ]
        },
        {
            "id": "IN-MAL-2026-010921",
            "import_time": "2026-07-28T14:19:59.158721787Z",
            "modified_time": "2026-07-28T13:36:41Z",
            "sha256": "a56bd768435fd324b7b5d037f8cac9bab5d1342c0d312c6647ff794c2ec66ef8",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-010926",
            "import_time": "2026-07-28T14:19:59.369761235Z",
            "modified_time": "2026-07-28T13:37:27Z",
            "sha256": "bd2f138e2aa5d09f80180c3818534c7bdbc77cb9346f27ef83e3ad9fe0466004",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-010920",
            "import_time": "2026-07-28T14:19:59.12124985Z",
            "modified_time": "2026-07-28T13:36:32Z",
            "sha256": "d6c90ac4a7a2227ca95b892b15beb34a88970aaa7729fd1584fcaa48a000c285",
            "source": "amazon-inspector",
            "versions": [
                "1.0.6"
            ]
        },
        {
            "id": "IN-MAL-2026-010922",
            "import_time": "2026-07-28T14:19:59.235646839Z",
            "modified_time": "2026-07-28T13:36:49Z",
            "sha256": "4a633182d940458c870c82422e6e43cedbcc01f9928eaac00f982798bc569e98",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-010927",
            "import_time": "2026-07-28T14:19:59.410539572Z",
            "modified_time": "2026-07-28T13:37:35Z",
            "sha256": "975cdc72d222f763e149ad095c127af814ec344161108f30d967153e24816801",
            "source": "amazon-inspector",
            "versions": [
                "1.0.10"
            ]
        },
        {
            "id": "IN-MAL-2026-010929",
            "import_time": "2026-07-28T14:19:59.519229867Z",
            "modified_time": "2026-07-28T13:37:53Z",
            "sha256": "c88c1ee649c0d3dec8a0d0326727f44bfe35f72f5537e988060be3157edc2b35",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-010907",
            "import_time": "2026-07-28T14:19:58.513102386Z",
            "modified_time": "2026-07-28T13:34:35Z",
            "sha256": "db5048ba840343b2dbeaf43ba302c6f36e2704b5a9ad510e656164d876c688c6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.9"
            ]
        },
        {
            "id": "IN-MAL-2026-010913",
            "import_time": "2026-07-28T14:19:58.774515655Z",
            "modified_time": "2026-07-28T13:35:30Z",
            "sha256": "fcfc1bc035f5239e384f9e32be4fc53cdffe065920da7c6181e42757d6b41195",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / easyway2

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "369e4ced330a5ced4d0d98ebc9f01f0258af3461f3c162b38e46305b20b5b358",
            "tlsh": "6bf00ce08005d46f9fc503a67ee28005d07a3a0aa103ac14da214ad72bcc26abcb8384"
        }
    ],
    "package_integrity": [
        {
            "filename": "easyway2-1.0.11.tgz",
            "hashes": {
                "sha1": "261bf2163d982bcce435c04646c371e832e3c9fe",
                "sha512_sri": "sha512-Bqtm2QwzecJ1MDI5FZq0SjxUJ+Fv2LXcvuUf5UkZZLYFBcTJ2zB/9IrZc+GNzOMALNl+VbBb5gzYZbet2MdX+Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/easyway2/MAL-2026-10769.json"