MAL-2026-11128

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/app-soda-layer/MAL-2026-11128.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11128
Published
2026-07-28T09:00:00Z
Modified
2026-08-06T04:19:38Z
Summary
Malicious code in app-soda-layer (npm)
Details

app-soda-layer 2.1.6 is an npm credential stealer and SSH backdoor that runs automatically on npm install through a postinstall hook (test.js). It harvests Solana keypairs (id.json), config.toml and .env secrets, then installs an operator-supplied SSH key into ~/.ssh/authorized_keys and opens port 22 for persistent access. Any host that installed it should be treated as compromised: check ~/.ssh/authorized_keys for the key below, check the firewall for a newly opened port 22, and rotate Solana keypairs, SSH keys and any secrets in reachable .env files. The package was purpose-built rather than a compromised library: its name and only version were created 284 ms apart with no earlier release, published 2026-07-27T18:47:46Z and unpublished by the author about 2.5 hours later, so it now returns 404 and survives only in sandbox capture.

The payload is a redeployment of the levex-refa/lint-builder toolkit documented in the February 2026 dev-protocol GitHub organization compromise, against new infrastructure. The exported function names, the authorized_keys/chown -R/ufw allow 22/tcp sequence, the /api/ssh-key, /api/scan-patterns, /api/block-patterns and /api/v1 endpoints, and the file-target list all match, and the same toolkit was reported in #1366 (polymarket-mcp-v2 2.1.6, C2 170.205.31.203). One routine POSTs a hardcoded id.json/config.toml/.env harvest to the C2 prefixed with the OS username; a second fetches a live pattern list and recursively uploads matches from the home directory, or from every logical drive on Windows via wmic/PowerShell. The infrastructure rotates per deployment while the code does not, so the stable indicators are the endpoint names and the injected SSH public key, whose comment field impersonates the support address of an unrelated company and is omitted here (match the base64 body): ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFYMx8MqdYTD/aZjqxmXo+9460+9EvsSjfiy9YAU+xwY. The pattern list retrieved live on 2026-07-28 was .env, .xls, .xlsx, privatekey, private key, seed, wallet, key, phrase, private (case-insensitive substring).


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f0857a9d8b1484b56b0ba1c671f5077125b8c898012aa57b0dd8813694206f53)

The package's postinstall hook (test.js) executes multiple malicious payloads on npm install. It walks the current working directory for files matching id.json, config.toml,.env, and env, and POSTs each to http://95.216.118.146:3000/api/v1 prefixed with the OS username. A second routine fetches attacker-controlled scan and block patterns from http://95.216.118.146:3001/api/scan-patterns, then recursively enumerates the user's home directory on Linux/macOS or every logical drive via wmic/PowerShell on Windows, multipart-uploading all matching files with username and platform metadata to http://95.216.118.146:3001/api/v1. On Linux, addSshKeyToUser() retrieves an SSH public key from http://95.216.118.146:3001/api/ssh-key, appends it to $HOME/.ssh/authorized_keys, chowns ~/.ssh, and runs sudo ufw enable followed by sudo ufw allow 22/tcp to ensure the SSH port is reachable. Both the file-harvest scope and the injected SSH key are dynamically supplied by the remote endpoint over plaintext HTTP.

Database specific
{
    "iocs": {
        "ips": [
            "95.216.118.146"
        ],
        "urls": [
            "http://95.216.118.146:3000/api/v1",
            "http://95.216.118.146:3001/api/v1",
            "http://95.216.118.146:3001/api/ssh-key",
            "http://95.216.118.146:3001/api/scan-patterns",
            "http://95.216.118.146:3001/api/block-patterns"
        ]
    },
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-010868",
            "import_time": "2026-07-28T14:19:56.596768159Z",
            "modified_time": "2026-07-28T13:29:26Z",
            "sha256": "f0857a9d8b1484b56b0ba1c671f5077125b8c898012aa57b0dd8813694206f53",
            "source": "amazon-inspector",
            "versions": [
                "2.1.6"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / app-soda-layer

Package

Name
app-soda-layer
View open source insights on deps.dev
Purl
pkg:npm/app-soda-layer

Affected ranges

Affected versions

2.*
2.1.6

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "816709b97cc4a1c5c0943813d804c3e8dee9e940bfa808bf4b86ddb10fcc523c",
            "tlsh": "0b02624c96fb2a21c2b371ac465f1406b59ac0033949cd91b6cc93546f8f93d69f2e9e"
        }
    ],
    "package_integrity": [
        {
            "filename": "app-soda-layer-2.1.6.tgz",
            "hashes": {
                "sha1": "eddb0444a94aa8b5e678c4906cbac333658556f8",
                "sha512_sri": "sha512-pevIbrCfrpAyun+xfHpeoc+tjvlIs+9NiOiFfz34xFzgV2bCgs0b4p9zCND3vI9s3UwqsI7WnflGMr27dKg1nw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/app-soda-layer/MAL-2026-11128.json"