MAL-2026-13611

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mangomind-agent/MAL-2026-13611.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13611
Published
2026-08-07T13:47:22Z
Modified
2026-08-07T14:49:43.745272068Z
Summary
Malicious code in mangomind-agent (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6512bd1cea27977e679186d569d524555fdf0ed5ea9e4b965aa640b1ae8326cb)

src/index.js opens a persistent WebSocket to a hardcoded default relay at wss://relay.mangomindbd.com and dispatches on message types received from that remote endpoint. On messages of type 'diagnosis' with autoFix set, the handler passes msg.fixCommand — a string chosen by whoever controls the relay — directly to childprocess.execSync on the local machine (timeout 120000ms), yielding full-host command execution under the user running the agent. On messages of type 'opencoderequest', the handler forwards attacker-chosen HTTP method, path, and body to a locally-spawned opencode AI coding agent bound on 127.0.0.1 and returns its response, giving the same remote party a proxied channel to drive that agent's file and shell tool access against the installer's workspace. The relay hostname mangomindbd.com is also referenced from https://api.mangomindbd.com in the same file, and the module makes cross-platform curl/http.get/os.hostname calls consistent with host-context reporting to the relay. The remote-execution paths are gated only by an initial token handshake with the relay operator, so any party in control of relay.mangomindbd.com holds arbitrary RCE and AI-agent-driven filesystem access on every host running this package.

Database specific
{
    "malicious-packages-origins": [
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-07T13:47:30Z",
            "sha256": "0a820627a381b679977138fc6a5c6b0c3e14223edc94ad95540da892a732f899",
            "import_time": "2026-08-07T14:26:55.197201565Z",
            "id": "IN-MAL-2026-017093",
            "versions": [
                "0.1.8"
            ]
        },
        {
            "modified_time": "2026-08-07T13:48:08Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-017098",
            "import_time": "2026-08-07T14:26:55.507571993Z",
            "sha256": "1138420f285343ebe7ca653e0fc496ff6df0e82fea9757611f64776e9940c2f0",
            "versions": [
                "0.1.2"
            ]
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-07T13:47:22Z",
            "sha256": "62dd36baa2ed2939bce3610e618a428a14a9c2ea99784813b4a36ab87e2621b6",
            "import_time": "2026-08-07T14:26:55.144307509Z",
            "id": "IN-MAL-2026-017092",
            "versions": [
                "0.1.5"
            ]
        },
        {
            "modified_time": "2026-08-07T13:48:16Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-017099",
            "import_time": "2026-08-07T14:26:55.574602281Z",
            "sha256": "6512bd1cea27977e679186d569d524555fdf0ed5ea9e4b965aa640b1ae8326cb",
            "versions": [
                "0.1.1"
            ]
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-07T13:48:01Z",
            "sha256": "8a8208cd174e0307751e38c5eef81f1ae0846462d50364f44a862155207860d0",
            "import_time": "2026-08-07T14:26:55.457072558Z",
            "id": "IN-MAL-2026-017097",
            "versions": [
                "0.1.0"
            ]
        },
        {
            "modified_time": "2026-08-07T13:47:45Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-017095",
            "import_time": "2026-08-07T14:26:55.367990045Z",
            "sha256": "f6b9d85fd3ae05d7dd1103bfd87b5a2b3331c324f7e05a6efff025922bf13fa5",
            "versions": [
                "0.1.4"
            ]
        },
        {
            "modified_time": "2026-08-07T13:47:51Z",
            "source": "amazon-inspector",
            "sha256": "7bc7cbb3a5ae03743640f64295f706a906cf879bee18ebf1061d6c636efa7924",
            "import_time": "2026-08-07T14:26:55.406479052Z",
            "id": "IN-MAL-2026-017096",
            "versions": [
                "0.1.7"
            ]
        },
        {
            "modified_time": "2026-08-07T13:48:35Z",
            "source": "amazon-inspector",
            "sha256": "ae63365cb47ed8a6d2442c04be2f5828ce003a53fab3d3a4a2498f4f7b1be274",
            "import_time": "2026-08-07T14:26:55.682966588Z",
            "id": "IN-MAL-2026-017101",
            "versions": [
                "0.2.0"
            ]
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-07T13:47:36Z",
            "id": "IN-MAL-2026-017094",
            "import_time": "2026-08-07T14:26:55.252366043Z",
            "sha256": "b94467feb1e9912a43e28661b777638d5445997a7c299152d792bf33407e38c2",
            "versions": [
                "0.1.3"
            ]
        },
        {
            "modified_time": "2026-08-07T13:48:28Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-017100",
            "import_time": "2026-08-07T14:26:55.618549591Z",
            "sha256": "e4b935a8a3b1227ebac8eee92165ea75600dfa3fbf3eece2969a5bbde299a4c6",
            "versions": [
                "0.2.1"
            ]
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-07T13:48:51Z",
            "id": "IN-MAL-2026-017103",
            "import_time": "2026-08-07T14:26:55.818903002Z",
            "sha256": "ee9a565cd1c79c46d573acd39abcd3c1e9c3e9167632a322f485b0a25cb589b7",
            "versions": [
                "0.1.6"
            ]
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-07T13:48:44Z",
            "id": "IN-MAL-2026-017102",
            "import_time": "2026-08-07T14:26:55.763271544Z",
            "sha256": "fa7568fdd1f991143971cfd19c3368bb2e41f99cf44c66bc72308ea32f0d7ffc",
            "versions": [
                "0.1.9"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / mangomind-agent

Package

Affected ranges

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.1

Database specific

indicators
{
    "package_integrity": [
        {
            "filename": "mangomind-agent-0.1.8.tgz",
            "hashes": {
                "sha512_sri": "sha512-SKfYYlb8PLtRDKfbJSxU6YDwElvSGDw3TUIK/7TPN9+PL1wi4kBvKXVZd6qQhdLKcqGQ4f+3HGMh3CuxOMDhFw==",
                "sha1": "32f3c03ee5c98e895551025fbc504dcb0991302c"
            }
        }
    ],
    "evidence_files": [
        {
            "tlsh": "5a824e3888b9112a7b43e26c9697502d3626b2533a192d507b8db3e85fcd43c50b37fd",
            "sha256": "0f74eafafaffca01af2a63dbdfecc0fd2e5ee28316cbaa9e64407c568a54f8e9",
            "path": "src/index.js"
        },
        {
            "tlsh": "bcf1833991615a797b52c3bf15cf2406269bb067b801a8907bec749cafdec2841338fd",
            "sha256": "9ddbcb282ad318cd6c8739fb8bd05c95cfdc54530423bc89c0ea11c723d4f2ff",
            "path": "src/autostart.js"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mangomind-agent/MAL-2026-13611.json"
cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature.",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]