-= Per source details. Do not edit below this line.=-
dist/index.js contains a startControlClient routine that reads OxaPay payment-gateway secrets (OXAPAY_GENERAL_API_KEY, OXAPAY_MERCHANT_API_KEY, OXAPAY_PAYOUT_API_KEY, OXAPAY_WEBHOOK_SECRET) from the environment together with host metadata (server IP from os.networkInterfaces, hostname label, resolved public domain from DOMAIN/NEXT_PUBLIC_SITE_URL/VERCEL_URL/NEXTAUTH_URL) and POSTs them to a hardcoded bare-IP controller at http://23.160.168.168:4141/register over plain HTTP. The same module opens a WebSocket to ws://23.160.168.168:4141/proxy-tunnel where the remote endpoint sends JSON 'open' messages with attacker-chosen host and port; the package then creates outbound TCP sockets to those destinations and bidirectionally relays base64-framed data, turning the host into an operator-controlled TCP relay. A second SSE channel at /events lets the controller terminate the running Node/Next.js process on a 'stop' event. The covert behavior is gated behind a verifyProjectImportCoverage check that enumerates the entire project source tree and only activates when every source file imports the companion package '@crb/xbr', so consumers who merely require the module during review see no network activity. The bare-IP destination is unrelated to any documented OxaPay infrastructure and is not caller-configurable.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-010949",
"import_time": "2026-07-28T14:20:00.752807769Z",
"modified_time": "2026-07-28T13:40:37Z",
"sha256": "058c590aee7b5df39e33a28dc448cec5cb2581e444824e0189546cdbb25df74d",
"source": "amazon-inspector",
"versions": [
"1.1.2"
]
},
{
"id": "IN-MAL-2026-010945",
"import_time": "2026-07-28T14:20:00.5553725Z",
"modified_time": "2026-07-28T13:40:07Z",
"sha256": "179d74e089794cb517fcb4030021310137bedcc72f0ef49362b4ce1724cb5ac3",
"source": "amazon-inspector",
"versions": [
"1.1.1"
]
},
{
"id": "IN-MAL-2026-010947",
"import_time": "2026-07-28T14:20:00.650502785Z",
"modified_time": "2026-07-28T13:40:24Z",
"sha256": "2c1ddda520378b6da51e744d1836d5e42ac1742beb6ea962140f5ab0252590ed",
"source": "amazon-inspector",
"versions": [
"1.2.1"
]
},
{
"id": "IN-MAL-2026-010948",
"import_time": "2026-07-28T14:20:00.709052368Z",
"modified_time": "2026-07-28T13:40:31Z",
"sha256": "4ac96741026b669e8078c6b1b72f7e63fc14d1bed42a753cca659033df7cd515",
"source": "amazon-inspector",
"versions": [
"1.1.3"
]
},
{
"id": "IN-MAL-2026-010951",
"import_time": "2026-07-28T14:20:01.044403257Z",
"modified_time": "2026-07-28T13:40:50Z",
"sha256": "968f26302e16e25cfe61a948b2020970c63f2e71aebb345ba19e801dcc950b19",
"source": "amazon-inspector",
"versions": [
"1.1.4"
]
},
{
"id": "IN-MAL-2026-010946",
"import_time": "2026-07-28T14:20:00.600972625Z",
"modified_time": "2026-07-28T13:40:14Z",
"sha256": "d26fb97a854e1338f2d0ec760231097de54f63a34fcbd9a2d8e47f73d5b4b8f3",
"source": "amazon-inspector",
"versions": [
"1.1.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.js",
"sha256": "b19241178eaf8c71a41893e0f24061fe994ea95f628e129b58f0bc187f73c189",
"tlsh": "76826549a9f3292446a3349da75b44167638e0033a0ccd18bbac93917f7a179d6f37ce"
},
{
"path": "src/config.ts",
"sha256": "090409429cda6389ca39bdca294d238fb7c14b585cd53703e89b3956c4930539",
"tlsh": "39c08c92e3961320c450048c620aea95220522a4aa1a408adcfe9a88106a148f4a35e2"
}
],
"package_integrity": [
{
"filename": "xbt-1.1.2.tgz",
"hashes": {
"sha1": "8cb29be9028b0c821251ee5037ec470ebeee0ec9",
"sha512_sri": "sha512-dCl3YkjaKpskfWHMDaD0TIJdT9x1hg5iPrCcLH1czw3yHKJKCAsT1kf8Y9Xh0wPMScT6GMT7uZ8sEihShkr8tA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@crbrc/xbt/MAL-2026-11122.json"