MAL-2026-13690

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@noobaihome/amis-uni-area-widget/MAL-2026-13690.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13690
Published
2026-08-10T11:54:13Z
Modified
2026-08-10T12:50:24.488131264Z
Summary
Malicious code in @noobaihome/amis-uni-area-widget (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561)

scripts/install.js runs during npm preinstall and performs three attacker-beneficial actions against the installer host. First, it unconditionally beacons installer identifiers (pid, base64-encoded process.cwd(), base64-encoded process.env.INITCWD, and a marker) over plain HTTP to the hardcoded bare-IP endpoint http://49.232.169.67:43817/bsrc-r260. Second, when a parent build manifest matches an internal marker, it downloads a shell script from http://49.232.169.67:80/slt via curl (with a wget fallback) and pipes the response into /bin/sh through spawnSync, giving the remote host arbitrary code execution on the installer at install time. Third, it fetches http://bsrc-ssrf.n.baidu-int.com/bsrcuid — an internal-network endpoint reachable only from inside a specific corporate network — and forwards the base64-encoded response body back to the same 49.232.169.67:43817 callback, characteristic of an SSRF-driven internal reconnaissance probe. The destination is a bare IPv4 address on plain HTTP with no relationship to any documented publisher, the fetched shell script is unpinned and unverified, and all three behaviors fire automatically on npm install.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-10T12:24:45.518303263Z",
            "id": "IN-MAL-2026-017240",
            "sha256": "15510a6c21ecdd743474138e5ce36700a133705b31ab4e9d1651d298feaf66f8",
            "modified_time": "2026-08-10T11:55:16Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-017242",
            "import_time": "2026-08-10T12:24:45.730864322Z",
            "sha256": "2518f3a152632cdb5e9fe503102eb09f8ba7b79a6b8ea5f9ecc193206a8c2b6b",
            "versions": [
                "1.0.8"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-10T11:55:33Z"
        },
        {
            "id": "IN-MAL-2026-017238",
            "import_time": "2026-08-10T12:24:45.280902346Z",
            "sha256": "517ad8810b4a12e80381570f0ec88b7b708d810c97a2a90711ae68172c9af51a",
            "versions": [
                "1.0.11"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-10T11:54:58Z"
        },
        {
            "id": "IN-MAL-2026-017241",
            "import_time": "2026-08-10T12:24:45.638971752Z",
            "sha256": "87b5f72e01a3ae3eabab4af272133f2a3536a47aa2444b8b810a241ac6ef8b09",
            "modified_time": "2026-08-10T11:55:26Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-017243",
            "import_time": "2026-08-10T12:24:45.883181069Z",
            "sha256": "9dc6a9f3ec560cd4e83b7682e81c6349aa184892de353e807c41b3576a59a743",
            "versions": [
                "1.0.4"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-10T11:55:42Z"
        },
        {
            "id": "IN-MAL-2026-017239",
            "import_time": "2026-08-10T12:24:45.412722281Z",
            "sha256": "c5d7fdcc7c80d935460b3c3080915e805c96d6ea904593786afd9d985439a511",
            "modified_time": "2026-08-10T11:55:07Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.6"
            ]
        },
        {
            "id": "IN-MAL-2026-017233",
            "import_time": "2026-08-10T12:24:44.812053977Z",
            "sha256": "ca5d69656e3a385d08858223b6c6ca2abbef7896020921f5319f874dd39588e4",
            "versions": [
                "1.0.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-10T11:54:13Z"
        },
        {
            "id": "IN-MAL-2026-017236",
            "import_time": "2026-08-10T12:24:45.087805026Z",
            "sha256": "1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561",
            "versions": [
                "1.0.2"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-10T11:54:41Z"
        },
        {
            "id": "IN-MAL-2026-017237",
            "import_time": "2026-08-10T12:24:45.182843879Z",
            "sha256": "9e842cae97f83fd281bc9949bf01908a87bd08d885cef712d2dd7c021601939e",
            "modified_time": "2026-08-10T11:54:51Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "import_time": "2026-08-10T12:24:45.003788111Z",
            "id": "IN-MAL-2026-017235",
            "sha256": "d055000a3d6bd5333d0c4edc67a78f31703a56f2766fec9227a7c611ddae3a55",
            "modified_time": "2026-08-10T11:54:29Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.10"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @noobaihome/amis-uni-area-widget

Package

Name
@noobaihome/amis-uni-area-widget
View open source insights on deps.dev
Purl
pkg:npm/%40noobaihome/amis-uni-area-widget

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.10
1.0.11

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@noobaihome/amis-uni-area-widget/MAL-2026-13690.json"
indicators
{
    "evidence_files": [
        {
            "path": "dist/bsrc-loader.js",
            "tlsh": "6171976729f728669b53d0d8a21b4826b61281433997c9f4b94c03942fc7074d573afd",
            "sha256": "7c2ddfe2a4d569f1059d7d5de6a8e7f220a5fdf8b37b14a1b0b688557ccd8dcd"
        }
    ],
    "package_integrity": [
        {
            "filename": "amis-uni-area-widget-1.0.7.tgz",
            "hashes": {
                "sha512_sri": "sha512-TDaYSBk06aimZebC/5I5kdQ6QrisSYxtfL9wstNy19pl++cO9sdEbVIw330AuoLlZyaIo3wKGF6cCYoqSQFSgw==",
                "sha1": "35ced38edc44097413f104270a7ecafaa039c952"
            }
        }
    ]
}