MAL-2026-13449

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/merchantweb-lang-cookie-reset/MAL-2026-13449.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13449
Published
2026-08-06T16:15:13Z
Modified
2026-08-07T14:49:44.483497625Z
Summary
Malicious code in merchantweb-lang-cookie-reset (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fff16333aa7ffc7fc2c7decc1458c23b7d89f8caacb5c6129ba76168d08ec4be)

package.json declares the sole dependency packet-table-thread-stream as a direct tarball URL to a non-npm host (https://artifacts.yosiroute.com/npm/packet-table-thread-stream), with no version pin and no integrity hash. The shrinkwrap marks that dependency hasInstallScript: true, so on npm install npm fetches opaque code from artifacts.yosiroute.com and executes its lifecycle scripts on the installer's machine, bypassing npm registry scanning. The wrapper package itself is a disposable shim: index.js is trivial (only re-exports name/version), and package.json metadata is placeholder (author: Package Registry, description: Generated package, repo: github.com/example/...). The package's only functional effect on install is pulling attacker-controlled code from a non-registry host into the installer's dependency tree and running its install scripts.

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-08-06T16:15:13Z",
            "id": "IN-MAL-2026-016667",
            "import_time": "2026-08-06T18:09:03.403884105Z",
            "versions": [
                "99.99.99"
            ],
            "source": "amazon-inspector",
            "sha256": "5b095c93acc24b5979596513da816a08ab69de453c893e346f8c825985d3ec0b"
        },
        {
            "modified_time": "2026-08-07T13:46:41Z",
            "id": "IN-MAL-2026-017089",
            "import_time": "2026-08-07T14:26:54.925407899Z",
            "versions": [
                "1.0.998"
            ],
            "source": "amazon-inspector",
            "sha256": "7e12670f9987338fc995e1eb0bf13cd6bf0949656b1cfdc16a1c87988f391029"
        },
        {
            "modified_time": "2026-08-07T13:46:57Z",
            "id": "IN-MAL-2026-017091",
            "import_time": "2026-08-07T14:26:55.066408883Z",
            "versions": [
                "2.0.0"
            ],
            "source": "amazon-inspector",
            "sha256": "1473abd9b4bdf4c1e4ae3ea2792df1a7b7767afadf997d2eb462be4e4812c9d4"
        },
        {
            "modified_time": "2026-08-07T13:45:57Z",
            "id": "IN-MAL-2026-017084",
            "import_time": "2026-08-07T14:26:54.610603265Z",
            "versions": [
                "0.1.999"
            ],
            "source": "amazon-inspector",
            "sha256": "6fdc64548a3943481f8f5e68ad242d3b24a4b2a54e43f4e1c4559dc3623b4148"
        },
        {
            "modified_time": "2026-08-07T13:46:07Z",
            "id": "IN-MAL-2026-017085",
            "import_time": "2026-08-07T14:26:54.703599192Z",
            "versions": [
                "0.999.999"
            ],
            "source": "amazon-inspector",
            "sha256": "b5168eae14721870b10af6cfc658a8692171995688bc5510d47d2875cf0b8e9f"
        },
        {
            "modified_time": "2026-08-07T13:46:24Z",
            "id": "IN-MAL-2026-017087",
            "import_time": "2026-08-07T14:26:54.813021245Z",
            "versions": [
                "0.1.0"
            ],
            "source": "amazon-inspector",
            "sha256": "c21581066774b18d7569363233c1dbd287cf32939ee1c06c86df5990667cff01"
        },
        {
            "versions": [
                "1.999.999"
            ],
            "id": "IN-MAL-2026-017090",
            "import_time": "2026-08-07T14:26:54.968911453Z",
            "modified_time": "2026-08-07T13:46:50Z",
            "source": "amazon-inspector",
            "sha256": "d58c93de4adbdacdad567bfcb3e7c0c12d59d7b55f05ecac8bebed49f63a204c"
        },
        {
            "versions": [
                "1.0.999"
            ],
            "id": "IN-MAL-2026-017088",
            "import_time": "2026-08-07T14:26:54.866495141Z",
            "modified_time": "2026-08-07T13:46:34Z",
            "source": "amazon-inspector",
            "sha256": "f8b4bd334cad5c530726d1072d7ef97d0d22c4d73f6def5a63c8a1a9bfea2598"
        },
        {
            "versions": [
                "0.0.999"
            ],
            "id": "IN-MAL-2026-017083",
            "import_time": "2026-08-07T14:26:54.555423536Z",
            "modified_time": "2026-08-07T13:45:44Z",
            "source": "amazon-inspector",
            "sha256": "fff16333aa7ffc7fc2c7decc1458c23b7d89f8caacb5c6129ba76168d08ec4be"
        },
        {
            "modified_time": "2026-08-07T13:46:16Z",
            "id": "IN-MAL-2026-017086",
            "import_time": "2026-08-07T14:26:54.745527734Z",
            "versions": [
                "0.0.6"
            ],
            "source": "amazon-inspector",
            "sha256": "4d66244af69164db5f24314f3e0e4f9dd478599763adbf9f6fbd0a6ea55c8cf0"
        }
    ]
}
References
Credits

Affected packages

npm / merchantweb-lang-cookie-reset

Package

Name
merchantweb-lang-cookie-reset
View open source insights on deps.dev
Purl
pkg:npm/merchantweb-lang-cookie-reset

Affected ranges

Affected versions

0.*
0.0.6
0.0.999
0.1.0
0.1.999
0.999.999
1.*
1.0.998
1.0.999
1.999.999
2.*
2.0.0
99.*
99.99.99

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/merchantweb-lang-cookie-reset/MAL-2026-13449.json"
indicators
{
    "package_integrity": [
        {
            "hashes": {
                "sha512_sri": "sha512-wB/2nNHxpKGl8UauABjQIxwQE/+IQs4Wy8epQ5dkazZidVQDthoW5fJSavfeg4iWEQ85LFLBJETUWfQy9aT7RQ==",
                "sha1": "ec87e43dfa088eb04e0e7390f0133169f71adf5d"
            },
            "filename": "merchantweb-lang-cookie-reset-99.99.99.tgz"
        }
    ],
    "evidence_files": [
        {
            "path": "npm-shrinkwrap.json",
            "tlsh": "1df04669c16a79f352d2a6e885758943a963c00f510c685dbb9cc019cf0e5ab34b5a08",
            "sha256": "08861f89f25f8a326cadf906823bb7a2a5c6c1b8cb619704c56dfa69e740d4a9"
        },
        {
            "path": "package.json",
            "tlsh": "ebf02038c618a6b34ad509d89c655843aa278d1fe208b8999bd2c13a870e09728be91d",
            "sha256": "1f24d7f512fba7b853e6ed55acb38035b7201621295739331daae1ef7f5653e0"
        }
    ]
}