MAL-2026-11122

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@crbrc/xbt/MAL-2026-11122.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11122
Published
2026-07-28T13:40:07Z
Modified
2026-07-28T14:37:17Z
Summary
Malicious code in @crbrc/xbt (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (179d74e089794cb517fcb4030021310137bedcc72f0ef49362b4ce1724cb5ac3)

dist/index.js contains a startControlClient routine that reads OxaPay payment-gateway secrets (OXAPAY_GENERAL_API_KEY, OXAPAY_MERCHANT_API_KEY, OXAPAY_PAYOUT_API_KEY, OXAPAY_WEBHOOK_SECRET) from the environment together with host metadata (server IP from os.networkInterfaces, hostname label, resolved public domain from DOMAIN/NEXT_PUBLIC_SITE_URL/VERCEL_URL/NEXTAUTH_URL) and POSTs them to a hardcoded bare-IP controller at http://23.160.168.168:4141/register over plain HTTP. The same module opens a WebSocket to ws://23.160.168.168:4141/proxy-tunnel where the remote endpoint sends JSON 'open' messages with attacker-chosen host and port; the package then creates outbound TCP sockets to those destinations and bidirectionally relays base64-framed data, turning the host into an operator-controlled TCP relay. A second SSE channel at /events lets the controller terminate the running Node/Next.js process on a 'stop' event. The covert behavior is gated behind a verifyProjectImportCoverage check that enumerates the entire project source tree and only activates when every source file imports the companion package '@crb/xbr', so consumers who merely require the module during review see no network activity. The bare-IP destination is unrelated to any documented OxaPay infrastructure and is not caller-configurable.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-010949",
            "import_time": "2026-07-28T14:20:00.752807769Z",
            "modified_time": "2026-07-28T13:40:37Z",
            "sha256": "058c590aee7b5df39e33a28dc448cec5cb2581e444824e0189546cdbb25df74d",
            "source": "amazon-inspector",
            "versions": [
                "1.1.2"
            ]
        },
        {
            "id": "IN-MAL-2026-010945",
            "import_time": "2026-07-28T14:20:00.5553725Z",
            "modified_time": "2026-07-28T13:40:07Z",
            "sha256": "179d74e089794cb517fcb4030021310137bedcc72f0ef49362b4ce1724cb5ac3",
            "source": "amazon-inspector",
            "versions": [
                "1.1.1"
            ]
        },
        {
            "id": "IN-MAL-2026-010947",
            "import_time": "2026-07-28T14:20:00.650502785Z",
            "modified_time": "2026-07-28T13:40:24Z",
            "sha256": "2c1ddda520378b6da51e744d1836d5e42ac1742beb6ea962140f5ab0252590ed",
            "source": "amazon-inspector",
            "versions": [
                "1.2.1"
            ]
        },
        {
            "id": "IN-MAL-2026-010948",
            "import_time": "2026-07-28T14:20:00.709052368Z",
            "modified_time": "2026-07-28T13:40:31Z",
            "sha256": "4ac96741026b669e8078c6b1b72f7e63fc14d1bed42a753cca659033df7cd515",
            "source": "amazon-inspector",
            "versions": [
                "1.1.3"
            ]
        },
        {
            "id": "IN-MAL-2026-010951",
            "import_time": "2026-07-28T14:20:01.044403257Z",
            "modified_time": "2026-07-28T13:40:50Z",
            "sha256": "968f26302e16e25cfe61a948b2020970c63f2e71aebb345ba19e801dcc950b19",
            "source": "amazon-inspector",
            "versions": [
                "1.1.4"
            ]
        },
        {
            "id": "IN-MAL-2026-010946",
            "import_time": "2026-07-28T14:20:00.600972625Z",
            "modified_time": "2026-07-28T13:40:14Z",
            "sha256": "d26fb97a854e1338f2d0ec760231097de54f63a34fcbd9a2d8e47f73d5b4b8f3",
            "source": "amazon-inspector",
            "versions": [
                "1.1.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @crbrc/xbt

Package

Name
@crbrc/xbt
View open source insights on deps.dev
Purl
pkg:npm/%40crbrc/xbt

Affected ranges

Affected versions

1.*
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.2.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/index.js",
            "sha256": "b19241178eaf8c71a41893e0f24061fe994ea95f628e129b58f0bc187f73c189",
            "tlsh": "76826549a9f3292446a3349da75b44167638e0033a0ccd18bbac93917f7a179d6f37ce"
        },
        {
            "path": "src/config.ts",
            "sha256": "090409429cda6389ca39bdca294d238fb7c14b585cd53703e89b3956c4930539",
            "tlsh": "39c08c92e3961320c450048c620aea95220522a4aa1a408adcfe9a88106a148f4a35e2"
        }
    ],
    "package_integrity": [
        {
            "filename": "xbt-1.1.2.tgz",
            "hashes": {
                "sha1": "8cb29be9028b0c821251ee5037ec470ebeee0ec9",
                "sha512_sri": "sha512-dCl3YkjaKpskfWHMDaD0TIJdT9x1hg5iPrCcLH1czw3yHKJKCAsT1kf8Y9Xh0wPMScT6GMT7uZ8sEihShkr8tA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@crbrc/xbt/MAL-2026-11122.json"