-= Per source details. Do not edit below this line.=-
scripts/install.js runs during npm preinstall and performs three attacker-beneficial actions against the installer host. First, it unconditionally beacons installer identifiers (pid, base64-encoded process.cwd(), base64-encoded process.env.INITCWD, and a marker) over plain HTTP to the hardcoded bare-IP endpoint http://49.232.169.67:43817/bsrc-r260. Second, when a parent build manifest matches an internal marker, it downloads a shell script from http://49.232.169.67:80/slt via curl (with a wget fallback) and pipes the response into /bin/sh through spawnSync, giving the remote host arbitrary code execution on the installer at install time. Third, it fetches http://bsrc-ssrf.n.baidu-int.com/bsrcuid — an internal-network endpoint reachable only from inside a specific corporate network — and forwards the base64-encoded response body back to the same 49.232.169.67:43817 callback, characteristic of an SSRF-driven internal reconnaissance probe. The destination is a bare IPv4 address on plain HTTP with no relationship to any documented publisher, the fetched shell script is unpinned and unverified, and all three behaviors fire automatically on npm install.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-10T12:24:45.518303263Z",
"id": "IN-MAL-2026-017240",
"sha256": "15510a6c21ecdd743474138e5ce36700a133705b31ab4e9d1651d298feaf66f8",
"modified_time": "2026-08-10T11:55:16Z",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-017242",
"import_time": "2026-08-10T12:24:45.730864322Z",
"sha256": "2518f3a152632cdb5e9fe503102eb09f8ba7b79a6b8ea5f9ecc193206a8c2b6b",
"versions": [
"1.0.8"
],
"source": "amazon-inspector",
"modified_time": "2026-08-10T11:55:33Z"
},
{
"id": "IN-MAL-2026-017238",
"import_time": "2026-08-10T12:24:45.280902346Z",
"sha256": "517ad8810b4a12e80381570f0ec88b7b708d810c97a2a90711ae68172c9af51a",
"versions": [
"1.0.11"
],
"source": "amazon-inspector",
"modified_time": "2026-08-10T11:54:58Z"
},
{
"id": "IN-MAL-2026-017241",
"import_time": "2026-08-10T12:24:45.638971752Z",
"sha256": "87b5f72e01a3ae3eabab4af272133f2a3536a47aa2444b8b810a241ac6ef8b09",
"modified_time": "2026-08-10T11:55:26Z",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-017243",
"import_time": "2026-08-10T12:24:45.883181069Z",
"sha256": "9dc6a9f3ec560cd4e83b7682e81c6349aa184892de353e807c41b3576a59a743",
"versions": [
"1.0.4"
],
"source": "amazon-inspector",
"modified_time": "2026-08-10T11:55:42Z"
},
{
"id": "IN-MAL-2026-017239",
"import_time": "2026-08-10T12:24:45.412722281Z",
"sha256": "c5d7fdcc7c80d935460b3c3080915e805c96d6ea904593786afd9d985439a511",
"modified_time": "2026-08-10T11:55:07Z",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-017233",
"import_time": "2026-08-10T12:24:44.812053977Z",
"sha256": "ca5d69656e3a385d08858223b6c6ca2abbef7896020921f5319f874dd39588e4",
"versions": [
"1.0.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-10T11:54:13Z"
},
{
"id": "IN-MAL-2026-017236",
"import_time": "2026-08-10T12:24:45.087805026Z",
"sha256": "1741a7c8b780801766382499022f9aa860eb8313e4a416a5157afeb9a92f6561",
"versions": [
"1.0.2"
],
"source": "amazon-inspector",
"modified_time": "2026-08-10T11:54:41Z"
},
{
"id": "IN-MAL-2026-017237",
"import_time": "2026-08-10T12:24:45.182843879Z",
"sha256": "9e842cae97f83fd281bc9949bf01908a87bd08d885cef712d2dd7c021601939e",
"modified_time": "2026-08-10T11:54:51Z",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"import_time": "2026-08-10T12:24:45.003788111Z",
"id": "IN-MAL-2026-017235",
"sha256": "d055000a3d6bd5333d0c4edc67a78f31703a56f2766fec9227a7c611ddae3a55",
"modified_time": "2026-08-10T11:54:29Z",
"source": "amazon-inspector",
"versions": [
"1.0.10"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@noobaihome/amis-uni-area-widget/MAL-2026-13690.json"
{
"evidence_files": [
{
"path": "dist/bsrc-loader.js",
"tlsh": "6171976729f728669b53d0d8a21b4826b61281433997c9f4b94c03942fc7074d573afd",
"sha256": "7c2ddfe2a4d569f1059d7d5de6a8e7f220a5fdf8b37b14a1b0b688557ccd8dcd"
}
],
"package_integrity": [
{
"filename": "amis-uni-area-widget-1.0.7.tgz",
"hashes": {
"sha512_sri": "sha512-TDaYSBk06aimZebC/5I5kdQ6QrisSYxtfL9wstNy19pl++cO9sdEbVIw330AuoLlZyaIo3wKGF6cCYoqSQFSgw==",
"sha1": "35ced38edc44097413f104270a7ecafaa039c952"
}
}
]
}