-= Per source details. Do not edit below this line.=-
The exported bootstrapCore() unconditionally initializes the event bus with a hardcoded amqps:// URL containing embedded credentials for the author's CloudAMQP broker at dog.lmq.cloudamqp.com/vgyuplrd, with no override parameter. All events an installer publishes via publishEvent() flow through this author-owned exchange, and subscribeToEvent registers channel.consume handlers that JSON-parse incoming AMQP messages and invoke installer-registered subscriber methods as instancemethodName — meaning any party in possession of the shipped broker credentials can push messages that trigger arbitrary decorator-registered handlers in the installer's process with attacker-chosen payloads. ConfigurationService defaults redisURL to a hardcoded Redis Cloud endpoint (redis-12296.fcrce173.eu-west-1-1.ec2.redns.redis-cloud.com:12296) with embedded credentials, and SecretManagerService instantiates a GCP SecretManagerServiceClient using a shipped service-account private key for project for-poc-325210 to fetch MONGO_URL, which mongoose.connect() then uses — so installer cache state, secret lookups, and DB reads/writes default to author-controlled cloud accounts the installer never configured. The compiled bundle additionally ships a live GCP service-account private key (lyxa-core@for-poc-325210.iam.gserviceaccount.com), three Firebase Admin private keys (projects for-poc-325210, lyxa-rider-88939, lyxa-shop), a Redis Cloud password, and the CloudAMQP credentials, giving any third party administrative access to the same author-owned backends that installers of this package transitively depend on.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-06T16:50:22Z",
"id": "IN-MAL-2026-016721",
"import_time": "2026-08-06T18:09:11.003923525Z",
"versions": [
"1.0.145-debug"
],
"source": "amazon-inspector",
"sha256": "0aab606a35cc885f17daa4b943ffbc1ee3e691adfffa24513e5741758090953e"
},
{
"versions": [
"1.0.144-test"
],
"id": "IN-MAL-2026-016725",
"import_time": "2026-08-06T18:09:11.491293923Z",
"modified_time": "2026-08-06T16:51:03Z",
"source": "amazon-inspector",
"sha256": "28e9b605fd0af18680342f725e028fc612744a47e2ddf6dc86b4352babc60bde"
},
{
"versions": [
"1.0.16"
],
"id": "IN-MAL-2026-016727",
"import_time": "2026-08-06T18:09:11.758606421Z",
"modified_time": "2026-08-06T16:51:25Z",
"source": "amazon-inspector",
"sha256": "9bc2087e4e8aefbb672176906a2c4024a3deb2b6b4114dcd2d75c5d222558588"
},
{
"modified_time": "2026-08-06T16:52:44Z",
"id": "IN-MAL-2026-016735",
"import_time": "2026-08-06T18:09:12.783949264Z",
"versions": [
"1.0.8-debug-1"
],
"source": "amazon-inspector",
"sha256": "e8f074d2f617feee28f5f09f393dd6810df53a03b48cd23111239972d4dc6f7c"
},
{
"modified_time": "2026-08-06T16:53:03Z",
"id": "IN-MAL-2026-016737",
"import_time": "2026-08-06T18:09:13.026656092Z",
"versions": [
"1.1.36"
],
"source": "amazon-inspector",
"sha256": "f9322cb3d37df8cb254835171dd2d48cee1076ae99e09344db7faa6c8ae15212"
},
{
"modified_time": "2026-08-06T16:52:55Z",
"id": "IN-MAL-2026-016736",
"import_time": "2026-08-06T18:09:12.901056584Z",
"versions": [
"1.1.47"
],
"source": "amazon-inspector",
"sha256": "c120262f3806a610de489ebcba7302780d2de23d17a488f5f234e4a7f3e13d65"
},
{
"versions": [
"1.0.201"
],
"id": "IN-MAL-2026-016728",
"import_time": "2026-08-06T18:09:11.919177255Z",
"modified_time": "2026-08-06T16:51:36Z",
"source": "amazon-inspector",
"sha256": "d4092c78614b93ae58f52ffada20d6d58314406edb72d0629e991148a6d0c8e4"
},
{
"modified_time": "2026-08-06T16:50:41Z",
"id": "IN-MAL-2026-016723",
"import_time": "2026-08-06T18:09:11.21947683Z",
"versions": [
"1.2.24"
],
"source": "amazon-inspector",
"sha256": "e4814f0506585fa3e90397e31051bcf2f7eb91f431f546f199b3ffe9afb51bc5"
},
{
"versions": [
"1.0.206"
],
"id": "IN-MAL-2026-016731",
"import_time": "2026-08-06T18:09:12.267990588Z",
"modified_time": "2026-08-06T16:52:04Z",
"source": "amazon-inspector",
"sha256": "9cafacec65b89c0bcfb7e67a3ddc0343a810ebebefec2b351341920e403545e9"
},
{
"modified_time": "2026-08-06T16:50:14Z",
"id": "IN-MAL-2026-016720",
"import_time": "2026-08-06T18:09:10.818619466Z",
"versions": [
"1.0.386"
],
"source": "amazon-inspector",
"sha256": "a25f0470927b0a29c20475fea96ba8ae11cc06b574aefea78b7359f2aca853ad"
},
{
"modified_time": "2026-08-06T16:52:22Z",
"id": "IN-MAL-2026-016733",
"import_time": "2026-08-06T18:09:12.564295904Z",
"versions": [
"1.0.23"
],
"source": "amazon-inspector",
"sha256": "d28aa236c1d0ad9141c90c5da56e1e7d859f64f6ad51b03fbe20de29606fba46"
},
{
"versions": [
"1.2.43"
],
"id": "IN-MAL-2026-016726",
"import_time": "2026-08-06T18:09:11.61875495Z",
"modified_time": "2026-08-06T16:51:14Z",
"source": "amazon-inspector",
"sha256": "311248c420ae79e6397bb7961b4f2ab734a76815214cfe411b81ec28f95e9b3b"
},
{
"versions": [
"1.0.56"
],
"id": "IN-MAL-2026-016739",
"import_time": "2026-08-06T18:09:13.253792022Z",
"modified_time": "2026-08-06T16:53:21Z",
"source": "amazon-inspector",
"sha256": "481ff2b9d0a967572af464a2cfe585ab185912cff1f7c8eb1fa22195171199a1"
},
{
"versions": [
"1.0.281"
],
"id": "IN-MAL-2026-016732",
"import_time": "2026-08-06T18:09:12.460752068Z",
"modified_time": "2026-08-06T16:52:12Z",
"source": "amazon-inspector",
"sha256": "5cf1130fa5c4ab011358f55541cb7e6ef97d3c399f680d04313d143f6260daf4"
},
{
"modified_time": "2026-08-06T16:50:52Z",
"id": "IN-MAL-2026-016724",
"import_time": "2026-08-06T18:09:11.34369105Z",
"versions": [
"1.0.13"
],
"source": "amazon-inspector",
"sha256": "94e7260ac245ed2753d2bb1457953b3dc3051bea86e74ef0e8e8679866b5a99b"
},
{
"versions": [
"1.0.333"
],
"id": "IN-MAL-2026-016734",
"import_time": "2026-08-06T18:09:12.668902698Z",
"modified_time": "2026-08-06T16:52:35Z",
"source": "amazon-inspector",
"sha256": "d2ae7e523e4ec08064360c7641b197eb9a0edc4906da8d4a61c29e0772e52bb1"
},
{
"versions": [
"1.0.79"
],
"id": "IN-MAL-2026-016722",
"import_time": "2026-08-06T18:09:11.114592811Z",
"modified_time": "2026-08-06T16:50:31Z",
"source": "amazon-inspector",
"sha256": "8810fa7234da9bf5bfd19d413f0c4b4e4fb82f178764d46b5db7c02a5caddf9c"
},
{
"versions": [
"1.0.37"
],
"id": "IN-MAL-2026-016738",
"import_time": "2026-08-06T18:09:13.142154077Z",
"modified_time": "2026-08-06T16:53:13Z",
"source": "amazon-inspector",
"sha256": "cedab42884ee8af136243a5af2230c36e900eb0207fb2b47c6e4f25c10d4596d"
},
{
"versions": [
"1.0.129"
],
"id": "IN-MAL-2026-016730",
"import_time": "2026-08-06T18:09:12.145993344Z",
"modified_time": "2026-08-06T16:51:55Z",
"source": "amazon-inspector",
"sha256": "1a32d4762c92b12ad7fd0567dfa0f07470a01884303acdc7a3585bfb4ad7fff2"
},
{
"modified_time": "2026-08-06T16:51:46Z",
"id": "IN-MAL-2026-016729",
"import_time": "2026-08-06T18:09:12.041449766Z",
"versions": [
"1.0.162-test"
],
"source": "amazon-inspector",
"sha256": "204fa170dfe32f0b2ef2e9be591f64578fedc097fd163b66fdf28758c6598990"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "core-1.0.145-debug.tgz",
"hashes": {
"sha512_sri": "sha512-+4n8tWB7hGiBoufbPsF3+A1e9qf2goWW8ovM7IKmYGYjZmdwh9VX5f5ro9EudOz10Qj4rfz0zCxwieAaQ55iEg==",
"sha1": "4ad3413f4e2ff858e3a1d5d1a39c4cc52628402a"
}
}
],
"evidence_files": [
{
"path": "index.js",
"tlsh": "12d122513bf794b2e137118a5b5b100b187bdb83b589f410b7fca326cfd35198297296",
"sha256": "a63d36c32da581d44ce579798426ded1ed01ce9c2989aa65427fedea6011d9a0"
},
{
"path": "libraries/event/index.js",
"tlsh": "dd41314d39fa1971463b30ae472b9842113db5dfb901dc54b7dcde618fe4844da92f90",
"sha256": "4f1b649d25540fde69427e3b851ba6d507fa16edb89295b0b2b3aeb11ce2c86b"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@lyxa.ai/core/MAL-2026-13434.json"