-= Per source details. Do not edit below this line.=-
src/index.js opens a persistent WebSocket to a hardcoded default relay at wss://relay.mangomindbd.com and dispatches on message types received from that remote endpoint. On messages of type 'diagnosis' with autoFix set, the handler passes msg.fixCommand — a string chosen by whoever controls the relay — directly to childprocess.execSync on the local machine (timeout 120000ms), yielding full-host command execution under the user running the agent. On messages of type 'opencoderequest', the handler forwards attacker-chosen HTTP method, path, and body to a locally-spawned opencode AI coding agent bound on 127.0.0.1 and returns its response, giving the same remote party a proxied channel to drive that agent's file and shell tool access against the installer's workspace. The relay hostname mangomindbd.com is also referenced from https://api.mangomindbd.com in the same file, and the module makes cross-platform curl/http.get/os.hostname calls consistent with host-context reporting to the relay. The remote-execution paths are gated only by an initial token handshake with the relay operator, so any party in control of relay.mangomindbd.com holds arbitrary RCE and AI-agent-driven filesystem access on every host running this package.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"modified_time": "2026-08-07T13:47:30Z",
"sha256": "0a820627a381b679977138fc6a5c6b0c3e14223edc94ad95540da892a732f899",
"import_time": "2026-08-07T14:26:55.197201565Z",
"id": "IN-MAL-2026-017093",
"versions": [
"0.1.8"
]
},
{
"modified_time": "2026-08-07T13:48:08Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-017098",
"import_time": "2026-08-07T14:26:55.507571993Z",
"sha256": "1138420f285343ebe7ca653e0fc496ff6df0e82fea9757611f64776e9940c2f0",
"versions": [
"0.1.2"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-07T13:47:22Z",
"sha256": "62dd36baa2ed2939bce3610e618a428a14a9c2ea99784813b4a36ab87e2621b6",
"import_time": "2026-08-07T14:26:55.144307509Z",
"id": "IN-MAL-2026-017092",
"versions": [
"0.1.5"
]
},
{
"modified_time": "2026-08-07T13:48:16Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-017099",
"import_time": "2026-08-07T14:26:55.574602281Z",
"sha256": "6512bd1cea27977e679186d569d524555fdf0ed5ea9e4b965aa640b1ae8326cb",
"versions": [
"0.1.1"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-07T13:48:01Z",
"sha256": "8a8208cd174e0307751e38c5eef81f1ae0846462d50364f44a862155207860d0",
"import_time": "2026-08-07T14:26:55.457072558Z",
"id": "IN-MAL-2026-017097",
"versions": [
"0.1.0"
]
},
{
"modified_time": "2026-08-07T13:47:45Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-017095",
"import_time": "2026-08-07T14:26:55.367990045Z",
"sha256": "f6b9d85fd3ae05d7dd1103bfd87b5a2b3331c324f7e05a6efff025922bf13fa5",
"versions": [
"0.1.4"
]
},
{
"modified_time": "2026-08-07T13:47:51Z",
"source": "amazon-inspector",
"sha256": "7bc7cbb3a5ae03743640f64295f706a906cf879bee18ebf1061d6c636efa7924",
"import_time": "2026-08-07T14:26:55.406479052Z",
"id": "IN-MAL-2026-017096",
"versions": [
"0.1.7"
]
},
{
"modified_time": "2026-08-07T13:48:35Z",
"source": "amazon-inspector",
"sha256": "ae63365cb47ed8a6d2442c04be2f5828ce003a53fab3d3a4a2498f4f7b1be274",
"import_time": "2026-08-07T14:26:55.682966588Z",
"id": "IN-MAL-2026-017101",
"versions": [
"0.2.0"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-07T13:47:36Z",
"id": "IN-MAL-2026-017094",
"import_time": "2026-08-07T14:26:55.252366043Z",
"sha256": "b94467feb1e9912a43e28661b777638d5445997a7c299152d792bf33407e38c2",
"versions": [
"0.1.3"
]
},
{
"modified_time": "2026-08-07T13:48:28Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-017100",
"import_time": "2026-08-07T14:26:55.618549591Z",
"sha256": "e4b935a8a3b1227ebac8eee92165ea75600dfa3fbf3eece2969a5bbde299a4c6",
"versions": [
"0.2.1"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-07T13:48:51Z",
"id": "IN-MAL-2026-017103",
"import_time": "2026-08-07T14:26:55.818903002Z",
"sha256": "ee9a565cd1c79c46d573acd39abcd3c1e9c3e9167632a322f485b0a25cb589b7",
"versions": [
"0.1.6"
]
},
{
"source": "amazon-inspector",
"modified_time": "2026-08-07T13:48:44Z",
"id": "IN-MAL-2026-017102",
"import_time": "2026-08-07T14:26:55.763271544Z",
"sha256": "fa7568fdd1f991143971cfd19c3368bb2e41f99cf44c66bc72308ea32f0d7ffc",
"versions": [
"0.1.9"
]
}
]
}{
"package_integrity": [
{
"filename": "mangomind-agent-0.1.8.tgz",
"hashes": {
"sha512_sri": "sha512-SKfYYlb8PLtRDKfbJSxU6YDwElvSGDw3TUIK/7TPN9+PL1wi4kBvKXVZd6qQhdLKcqGQ4f+3HGMh3CuxOMDhFw==",
"sha1": "32f3c03ee5c98e895551025fbc504dcb0991302c"
}
}
],
"evidence_files": [
{
"tlsh": "5a824e3888b9112a7b43e26c9697502d3626b2533a192d507b8db3e85fcd43c50b37fd",
"sha256": "0f74eafafaffca01af2a63dbdfecc0fd2e5ee28316cbaa9e64407c568a54f8e9",
"path": "src/index.js"
},
{
"tlsh": "bcf1833991615a797b52c3bf15cf2406269bb067b801a8907bec749cafdec2841338fd",
"sha256": "9ddbcb282ad318cd6c8739fb8bd05c95cfdc54530423bc89c0ea11c723d4f2ff",
"path": "src/autostart.js"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mangomind-agent/MAL-2026-13611.json"
[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]