-= Per source details. Do not edit below this line.=-
package.json declares the sole dependency packet-table-thread-stream as a direct tarball URL to a non-npm host (https://artifacts.yosiroute.com/npm/packet-table-thread-stream), with no version pin and no integrity hash. The shrinkwrap marks that dependency hasInstallScript: true, so on npm install npm fetches opaque code from artifacts.yosiroute.com and executes its lifecycle scripts on the installer's machine, bypassing npm registry scanning. The wrapper package itself is a disposable shim: index.js is trivial (only re-exports name/version), and package.json metadata is placeholder (author: Package Registry, description: Generated package, repo: github.com/example/...). The package's only functional effect on install is pulling attacker-controlled code from a non-registry host into the installer's dependency tree and running its install scripts.
{
"malicious-packages-origins": [
{
"modified_time": "2026-08-06T16:15:13Z",
"id": "IN-MAL-2026-016667",
"import_time": "2026-08-06T18:09:03.403884105Z",
"versions": [
"99.99.99"
],
"source": "amazon-inspector",
"sha256": "5b095c93acc24b5979596513da816a08ab69de453c893e346f8c825985d3ec0b"
},
{
"modified_time": "2026-08-07T13:46:41Z",
"id": "IN-MAL-2026-017089",
"import_time": "2026-08-07T14:26:54.925407899Z",
"versions": [
"1.0.998"
],
"source": "amazon-inspector",
"sha256": "7e12670f9987338fc995e1eb0bf13cd6bf0949656b1cfdc16a1c87988f391029"
},
{
"modified_time": "2026-08-07T13:46:57Z",
"id": "IN-MAL-2026-017091",
"import_time": "2026-08-07T14:26:55.066408883Z",
"versions": [
"2.0.0"
],
"source": "amazon-inspector",
"sha256": "1473abd9b4bdf4c1e4ae3ea2792df1a7b7767afadf997d2eb462be4e4812c9d4"
},
{
"modified_time": "2026-08-07T13:45:57Z",
"id": "IN-MAL-2026-017084",
"import_time": "2026-08-07T14:26:54.610603265Z",
"versions": [
"0.1.999"
],
"source": "amazon-inspector",
"sha256": "6fdc64548a3943481f8f5e68ad242d3b24a4b2a54e43f4e1c4559dc3623b4148"
},
{
"modified_time": "2026-08-07T13:46:07Z",
"id": "IN-MAL-2026-017085",
"import_time": "2026-08-07T14:26:54.703599192Z",
"versions": [
"0.999.999"
],
"source": "amazon-inspector",
"sha256": "b5168eae14721870b10af6cfc658a8692171995688bc5510d47d2875cf0b8e9f"
},
{
"modified_time": "2026-08-07T13:46:24Z",
"id": "IN-MAL-2026-017087",
"import_time": "2026-08-07T14:26:54.813021245Z",
"versions": [
"0.1.0"
],
"source": "amazon-inspector",
"sha256": "c21581066774b18d7569363233c1dbd287cf32939ee1c06c86df5990667cff01"
},
{
"versions": [
"1.999.999"
],
"id": "IN-MAL-2026-017090",
"import_time": "2026-08-07T14:26:54.968911453Z",
"modified_time": "2026-08-07T13:46:50Z",
"source": "amazon-inspector",
"sha256": "d58c93de4adbdacdad567bfcb3e7c0c12d59d7b55f05ecac8bebed49f63a204c"
},
{
"versions": [
"1.0.999"
],
"id": "IN-MAL-2026-017088",
"import_time": "2026-08-07T14:26:54.866495141Z",
"modified_time": "2026-08-07T13:46:34Z",
"source": "amazon-inspector",
"sha256": "f8b4bd334cad5c530726d1072d7ef97d0d22c4d73f6def5a63c8a1a9bfea2598"
},
{
"versions": [
"0.0.999"
],
"id": "IN-MAL-2026-017083",
"import_time": "2026-08-07T14:26:54.555423536Z",
"modified_time": "2026-08-07T13:45:44Z",
"source": "amazon-inspector",
"sha256": "fff16333aa7ffc7fc2c7decc1458c23b7d89f8caacb5c6129ba76168d08ec4be"
},
{
"modified_time": "2026-08-07T13:46:16Z",
"id": "IN-MAL-2026-017086",
"import_time": "2026-08-07T14:26:54.745527734Z",
"versions": [
"0.0.6"
],
"source": "amazon-inspector",
"sha256": "4d66244af69164db5f24314f3e0e4f9dd478599763adbf9f6fbd0a6ea55c8cf0"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/merchantweb-lang-cookie-reset/MAL-2026-13449.json"
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-wB/2nNHxpKGl8UauABjQIxwQE/+IQs4Wy8epQ5dkazZidVQDthoW5fJSavfeg4iWEQ85LFLBJETUWfQy9aT7RQ==",
"sha1": "ec87e43dfa088eb04e0e7390f0133169f71adf5d"
},
"filename": "merchantweb-lang-cookie-reset-99.99.99.tgz"
}
],
"evidence_files": [
{
"path": "npm-shrinkwrap.json",
"tlsh": "1df04669c16a79f352d2a6e885758943a963c00f510c685dbb9cc019cf0e5ab34b5a08",
"sha256": "08861f89f25f8a326cadf906823bb7a2a5c6c1b8cb619704c56dfa69e740d4a9"
},
{
"path": "package.json",
"tlsh": "ebf02038c618a6b34ad509d89c655843aa278d1fe208b8999bd2c13a870e09728be91d",
"sha256": "1f24d7f512fba7b853e6ed55acb38035b7201621295739331daae1ef7f5653e0"
}
]
}