MAL-2026-10893

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ecto-cargo-wk1tm59a/MAL-2026-10893.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10893
Aliases
  • GHSA-wx6c-2wgg-hcwq
Published
2026-07-20T10:40:54Z
Modified
2026-09-01T11:30:36Z
Summary
Malicious code in ecto-cargo-wk1tm59a (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29)

Package ecto-cargo-wk1tm59a@99.0.0 exhibits several contextual red flags worth human review: a randomized-suffix name pattern (-wk1tm59a) typical of disposable/throwaway publishes, an inflated 99.0.0 version typical of dependency-confusion / proof-of-concept publishes, and only 3 files in the tarball. Automated content inspection of the package's code did not produce a usable trace, but the content was non-trivial enough that an automated description could not be produced. No specific attacker domain, exfiltration endpoint, or install-time fetch-and-execute behavior has been concretely identified from the available evidence, so a public block verdict is not justified, but the combination of disposable-name shape, 99.0.0 version inflation, and untraced contents warrants human inspection before this package is trusted.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-05530",
            "import_time": "2026-07-20T13:14:45.643678329Z",
            "modified_time": "2026-07-20T10:40:54Z",
            "sha256": "4d658031a727ec8ae264cb396f9e130d1c4cb8c28f803b2275bb45a09fb01507",
            "source": "reversing-labs",
            "versions": [
                "99.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-012955",
            "import_time": "2026-08-05T06:00:24.08053767Z",
            "modified_time": "2026-08-05T05:13:06Z",
            "sha256": "ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        },
        {
            "id": "RLUA-2026-06181",
            "import_time": "2026-09-01T11:18:02.141968377Z",
            "modified_time": "2026-08-24T16:48:14Z",
            "sha256": "e53b8340ac7ffea00b9252f6026d200b5552e4c5a35aa338a09b00fc2812c70f",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / ecto-cargo-wk1tm59a

Package

Name
ecto-cargo-wk1tm59a
View open source insights on deps.dev
Purl
pkg:npm/ecto-cargo-wk1tm59a

Affected ranges

Affected versions

99.*
99.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "ecto-cargo-wk1tm59a-99.0.0.tgz",
            "hashes": {
                "sha1": "b1da901e3c4763b49cf7e736a21c76c44c0446d2",
                "sha512_sri": "sha512-l5wZqLuVciZB1UWmCFkeiqvPN6wwoqGcEgWC9u6VT+LPqYC0E9bLba3jt/da5aOGZLwQoBYxZZKozCrnJ2/7vA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ecto-cargo-wk1tm59a/MAL-2026-10893.json"