-= Per source details. Do not edit below this line.=-
Package ecto-cargo-wk1tm59a@99.0.0 exhibits several contextual red flags worth human review: a randomized-suffix name pattern (-wk1tm59a) typical of disposable/throwaway publishes, an inflated 99.0.0 version typical of dependency-confusion / proof-of-concept publishes, and only 3 files in the tarball. Automated content inspection of the package's code did not produce a usable trace, but the content was non-trivial enough that an automated description could not be produced. No specific attacker domain, exfiltration endpoint, or install-time fetch-and-execute behavior has been concretely identified from the available evidence, so a public block verdict is not justified, but the combination of disposable-name shape, 99.0.0 version inflation, and untraced contents warrants human inspection before this package is trusted.
{
"malicious-packages-origins": [
{
"id": "RLMA-2026-05530",
"import_time": "2026-07-20T13:14:45.643678329Z",
"modified_time": "2026-07-20T10:40:54Z",
"sha256": "4d658031a727ec8ae264cb396f9e130d1c4cb8c28f803b2275bb45a09fb01507",
"source": "reversing-labs",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-012955",
"import_time": "2026-08-05T06:00:24.08053767Z",
"modified_time": "2026-08-05T05:13:06Z",
"sha256": "ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
},
{
"id": "RLUA-2026-06181",
"import_time": "2026-09-01T11:18:02.141968377Z",
"modified_time": "2026-08-24T16:48:14Z",
"sha256": "e53b8340ac7ffea00b9252f6026d200b5552e4c5a35aa338a09b00fc2812c70f",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"filename": "ecto-cargo-wk1tm59a-99.0.0.tgz",
"hashes": {
"sha1": "b1da901e3c4763b49cf7e736a21c76c44c0446d2",
"sha512_sri": "sha512-l5wZqLuVciZB1UWmCFkeiqvPN6wwoqGcEgWC9u6VT+LPqYC0E9bLba3jt/da5aOGZLwQoBYxZZKozCrnJ2/7vA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ecto-cargo-wk1tm59a/MAL-2026-10893.json"