-= Per source details. Do not edit below this line.=-
package.json declares postinstall: node test.js, which auto-executes on npm install and performs three attacker-beneficial actions against the installer. First, it recursively walks process.cwd() for id.json, config.toml, Config.toml, env, and .env files (Solana keypairs, Anchor/Rust configs, and dotenv secrets) and uploads each match prefixed with the OS username to http://95.216.118.146:3000/api/v1. Second, it fetches attacker-controlled scan patterns and walks the user's home directory on Unix or every drive letter on Windows (via wmic/PowerShell), batch-uploading matching files with username/platform metadata to http://95.216.118.146:3001/api/v1. Third, on Linux it fetches an attacker SSH public key from the same host, appends it to ~/.ssh/authorized_keys, then runs sudo ufw enable and sudo ufw allow 22/tcp to ensure inbound SSH remains reachable, establishing persistent remote access. Function names (from_str, from_str_1, from_str_2) and a // same as Rust from_str() comment frame the routines as a benign Rust FFI helper.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-04T21:10:55Z",
"sha256": "c8c77b8796f45d4e9888fe751dac62ad9f85334f29a64d8b0b2f50377611d6fc",
"id": "IN-MAL-2026-010974",
"versions": [
"2.1.6"
],
"import_time": "2026-08-04T21:33:11.835371594Z"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-dpOK72xttP2QgFtDvJ0Gd8BGpXzJfwN3m7zI3XryZC1ZOgFywCSAYZu5093Uak7H+a2gC2BeRKjHUgElNOblXw==",
"sha1": "21d13941344d7744b7ad8ee6dc3cf23bef9c53f8"
},
"filename": "nagix-node-2.1.6.tgz"
}
],
"evidence_files": [
{
"path": "index.js",
"sha256": "816709b97cc4a1c5c0943813d804c3e8dee9e940bfa808bf4b86ddb10fcc523c",
"tlsh": "0b02624c96fb2a21c2b371ac465f1406b59ac0033949cd91b6cc93546f8f93d69f2e9e"
},
{
"path": "package.json",
"sha256": "d0b059aec895f3ad959b4bf7aa92f8d25e835087f8bb7d518f1c0f8b0351ccef",
"tlsh": "8ef0ed27ce188e6328f135a8287c0617f691932f4100880f35fd664c4fb72330085f1e"
},
{
"path": "test.js",
"sha256": "ea505bd54c3ce4b4640b80220057fbb88d28a62cb5edbbf53cf3caf4dc123a8f",
"tlsh": "61d0c79814ba3132c42262fc672f3413ddb3d1972952ca60730f81164f764bd7435ead"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nagix-node/MAL-2026-11525.json"