-= Per source details. Do not edit below this line.=-
multi-acct@99.99.99 is a near-empty wrapper (index.js is a two-line stub returning name/version literals; author is the generic 'Package Registry' and repository.url points at an example.com-style placeholder). Its sole functional dependency, vector-cursor-stream-engine, is not resolved from the npm registry but from a hardcoded third-party HTTPS URL, https://artifacts.yosiroute.com/npm/vector-cursor-stream-engine, and the shrinkwrap marks that dependency as hasInstallScript:true. On npm install, npm downloads the tarball from artifacts.yosiroute.com and executes its lifecycle scripts, so whoever controls that host gets arbitrary code execution on the installer's machine. The URL is unpinned and carries no integrity hash, so the delivered bytes can change at any time. The wrapper shape (placeholder metadata, trivial main, single off-registry dependency with install scripts) matches a dependency-confusion / lure package whose real payload is delivered through the fetched sub-tarball.
{
"malicious-packages-origins": [
{
"versions": [
"99.99.99"
],
"id": "IN-MAL-2026-015867",
"import_time": "2026-08-05T19:04:55.923794601Z",
"modified_time": "2026-08-05T18:27:15Z",
"source": "amazon-inspector",
"sha256": "395e9271172eea5db15a1090043ee564ad6b8564fb9e267faff883ac3c6af125"
},
{
"modified_time": "2026-08-05T18:26:33Z",
"id": "IN-MAL-2026-015863",
"import_time": "2026-08-05T19:04:55.527279907Z",
"versions": [
"3.1.0"
],
"source": "amazon-inspector",
"sha256": "537efbfe863db4505906ce7ce76969cc2fdb0bf36bb288252e74c8627afb3ab6"
},
{
"modified_time": "2026-08-05T18:26:54Z",
"id": "IN-MAL-2026-015865",
"import_time": "2026-08-05T19:04:55.80937532Z",
"versions": [
"4.999.999"
],
"source": "amazon-inspector",
"sha256": "5cbd22202d671c96709714882629ae437c40992e4f27cc91e954330f724c0027"
},
{
"versions": [
"3.0.999"
],
"id": "IN-MAL-2026-015860",
"import_time": "2026-08-05T19:04:55.300170961Z",
"modified_time": "2026-08-05T18:26:07Z",
"source": "amazon-inspector",
"sha256": "60d77744c7151848ebfbf3477444411e658c18d995d95baf576716b1eac7f694"
},
{
"versions": [
"3.999.999"
],
"id": "IN-MAL-2026-015862",
"import_time": "2026-08-05T19:04:55.43207498Z",
"modified_time": "2026-08-05T18:26:24Z",
"source": "amazon-inspector",
"sha256": "c40d14e8ea1304684bdac199e92e1dde7c33871d8afd392c786dbb5eb015d359"
},
{
"versions": [
"2.0.999"
],
"id": "IN-MAL-2026-015866",
"import_time": "2026-08-05T19:04:55.863422336Z",
"modified_time": "2026-08-05T18:27:06Z",
"source": "amazon-inspector",
"sha256": "53a69278502ffc07c6c585ed448b72da7de25d2d658f07d2b2f70351c500be68"
},
{
"modified_time": "2026-08-05T18:25:48Z",
"id": "IN-MAL-2026-015858",
"import_time": "2026-08-05T19:04:55.131230993Z",
"versions": [
"4.0.0"
],
"source": "amazon-inspector",
"sha256": "716d679584225db14fb18102e7050dd6b2456f98e724e12edbe06bb12e221478"
},
{
"modified_time": "2026-08-05T18:25:59Z",
"id": "IN-MAL-2026-015859",
"import_time": "2026-08-05T19:04:55.222144039Z",
"versions": [
"2.1.999"
],
"source": "amazon-inspector",
"sha256": "8fc75b689b3d35e796e0c6dd3740c9a838e56ae0767b3c84123b684d70a9e1ed"
},
{
"versions": [
"1.0.0"
],
"id": "IN-MAL-2026-015864",
"import_time": "2026-08-05T19:04:55.714640708Z",
"modified_time": "2026-08-05T18:26:41Z",
"source": "amazon-inspector",
"sha256": "92458ab2b15c2634dfd809251eaa9ad2964ca323b79ad27387eeadb1fc6e9b1e"
},
{
"modified_time": "2026-08-05T18:26:16Z",
"id": "IN-MAL-2026-015861",
"import_time": "2026-08-05T19:04:55.362319477Z",
"versions": [
"2.999.999"
],
"source": "amazon-inspector",
"sha256": "b6cefd676a14a09191eeb1883554f337fc43d09cd2ec47e6257c091e8460d475"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "multi-acct-99.99.99.tgz",
"hashes": {
"sha512_sri": "sha512-0tubW7SiNeEf6dLmYXmZ6BoqhuwOs8uTI4glNLH4FxtVlyfPLNh4UCP2Wm7ZrT8MvJRxB8BulZEUePydbF7rYg==",
"sha1": "5ea2d40053dcb0e68c0f32622c203809a9673c42"
}
}
],
"evidence_files": [
{
"path": "package.json",
"tlsh": "b4e0ab71bc28d5b306d50b908ca2460bb6220c4bc40cec9c9783412d968c5532af825c",
"sha256": "da09ddfd57f36bd9a1103885d31c77fbe6ad557917ceba318452172d4ad1f5be"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/multi-acct/MAL-2026-13371.json"