MAL-2026-12797

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/multi-reqs/MAL-2026-12797.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-12797
Published
2026-08-05T13:19:10Z
Modified
2026-08-05T16:51:06.967606107Z
Summary
Malicious code in multi-reqs (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce)

The package's default export accepts (token, password) arguments and POSTs them, formatted as a Discord embed titled 'Yeni Hesap Bilgisi' with fields '🔑 Token' and '🔒 Şifre', to a hardcoded discord.com webhook URL. The destination is non-configurable, and any consumer that imports multi-reqs and invokes the default function forwards those credentials to an author-controlled Discord channel. Parameter naming and the Turkish 'Hesap Yönetim Sistemi' (Account Management System) framing indicate the module is designed to be consumed or bundled into other code as a credential-harvesting shim.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T13:19:10Z",
            "sha256": "2c03bde07a2a75531f18734b6986de0c59cd7d75400c665e4e059fb18b42996f",
            "id": "IN-MAL-2026-014971",
            "versions": [
                "1.0.2"
            ],
            "import_time": "2026-08-05T14:19:48.089416611Z"
        },
        {
            "import_time": "2026-08-05T14:19:48.263489273Z",
            "sha256": "633363514a8110d1ba6af50ac4431fa5e3bccb5e3692222d856747f10e6397ac",
            "modified_time": "2026-08-05T13:19:24Z",
            "id": "IN-MAL-2026-014973",
            "versions": [
                "1.0.3"
            ],
            "source": "amazon-inspector"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T13:19:31Z",
            "sha256": "a3d70b2617fc2d0158533bc541e04b68263a1e07ee2057c439c43ec40b073ad4",
            "id": "IN-MAL-2026-014974",
            "versions": [
                "1.0.0"
            ],
            "import_time": "2026-08-05T14:19:48.362582657Z"
        },
        {
            "import_time": "2026-08-05T16:13:46.256938358Z",
            "modified_time": "2026-08-05T15:41:46Z",
            "sha256": "38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce",
            "id": "IN-MAL-2026-015797",
            "versions": [
                "1.0.1"
            ],
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / multi-reqs

Package

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-qbzYlS7jCHKsBSfWaH8HWU71TekI4mt2/4/RhFWkGSUBe5o6kc2rUECV3MGcKJIvQni75xrKlITKEVS5VR23uQ==",
                "sha1": "3d01007ae24582630cef1ee681590a98c8215acc"
            },
            "filename": "multi-reqs-1.0.2.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "7cc40c2f862b243fdba1922cc830bee717b39f6368d4812dd0cd8328fceaeddc",
            "tlsh": "cc01449fd8bb09a18807bd569e4f80002319e0570c1bac74bbdcc3194fed82d58f2698"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/multi-reqs/MAL-2026-12797.json"