-= Per source details. Do not edit below this line.=-
Static keyword matches fired on the co-occurrence of tokens like 'curl', 'ping', 'POST', and 'GET' inside SDK/orchestrator source files (bin/room-orchestrator-boot.js, src/sdk/RoomOrchestrator.js, src/sdk/ServerAPI.js, src/sharding/RegionRouter.js). These are consistent with an orchestrator/routing SDK that performs latency probes and HTTP requests against its own service endpoints — the shape of a room/region networking client, not of an exfiltration primitive. No specific installer-side secret is shown being read (no ~/.aws, ~/.ssh, ~/.npmrc, env-var scraping, browser profile access), no hardcoded attacker C2 destination is named in evidence, and no lifecycle hook or top-level require-time execution path invoking these calls is demonstrated. Keyword co-occurrence in networking code is the shared shape of legitimate HTTP clients and cannot by itself establish exfiltration intent.
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-11T00:38:01.335302123Z",
"id": "GHSA-72h3-pwwh-68cx",
"sha256": "4952c46b3a196baaec2d02092303fb499978b121dd6dac73c2f98e193985690c",
"modified_time": "2026-08-10T19:41:26Z",
"source": "ghsa-malware",
"versions": [
"0.1.700",
"0.1.699",
"0.1.698",
"0.1.697",
"0.1.696",
"0.1.695"
]
},
{
"id": "IN-MAL-2026-017315",
"import_time": "2026-08-11T12:23:07.635400408Z",
"sha256": "0b5eca78abf186e88f60db7c00b85c754a90bc1a7c0c48cb456a470d58ff1485",
"modified_time": "2026-08-11T12:02:34Z",
"source": "amazon-inspector",
"versions": [
"0.1.699"
]
},
{
"id": "IN-MAL-2026-017314",
"import_time": "2026-08-11T12:23:07.559394715Z",
"sha256": "4c32e6b328bf731b6269e720e0fda2dec5264452ef04d406fde5296413424525",
"modified_time": "2026-08-11T12:02:27Z",
"source": "amazon-inspector",
"versions": [
"0.1.698"
]
},
{
"id": "IN-MAL-2026-017313",
"import_time": "2026-08-11T12:23:07.481651933Z",
"sha256": "6bfa1c21469868ae5950579a4af61e6076522fa5a9cff7443e6b2917a557067c",
"modified_time": "2026-08-11T12:02:17Z",
"source": "amazon-inspector",
"versions": [
"0.1.696"
]
},
{
"id": "IN-MAL-2026-017318",
"import_time": "2026-08-11T12:23:07.920157081Z",
"sha256": "7f6209ddfa258d9362c7060c0dc1bd28610181501cc884872f85e50533eaf49d",
"modified_time": "2026-08-11T12:02:58Z",
"source": "amazon-inspector",
"versions": [
"0.1.697"
]
},
{
"id": "IN-MAL-2026-017316",
"import_time": "2026-08-11T12:23:07.763880735Z",
"sha256": "e2b76568887dfe3df4247a4e094e9bac4284ada65e97407d31aa41c54705c831",
"modified_time": "2026-08-11T12:02:43Z",
"source": "amazon-inspector",
"versions": [
"0.1.700"
]
},
{
"id": "IN-MAL-2026-017312",
"import_time": "2026-08-11T12:23:07.382500808Z",
"sha256": "f8379cb9c8409d5f8d72ea944ba717a58bca21ae8bac69e568364a2e517a8704",
"versions": [
"0.1.695"
],
"source": "amazon-inspector",
"modified_time": "2026-08-11T12:02:10Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "bin/room-orchestrator-boot.js",
"tlsh": "3632869b29ad5a275f83a3e9140f12477f66c50be5864890f30d83383bd663d42f29e9",
"sha256": "9bcc3a27c38a72c5b1156334da34c97734f8ed957829ae1cd0ae3ac3d61dd1a7"
},
{
"path": "src/sdk/RoomOrchestrator.js",
"tlsh": "4bf2b61663fc5222aa5353a07c1e1703ff59801ba6860954bb8c83ac7fdf13542bade5",
"sha256": "22fd973662798c56c2a35742e991ecb0d5a5e783cbb80d5476ab81d377530c13"
},
{
"path": "src/sdk/ServerAPI.js",
"tlsh": "2ec21946e6a8033a4e426579eb1f6111bb35c1ab1211fea0b66fd35dbf4603803773e6",
"sha256": "d3510bd019b3f712f09edf0c76562fdab691c1399f095dc527f5052e07f9cc78"
},
{
"path": "src/sharding/RegionRouter.js",
"tlsh": "6d72c62a1bb900b9c792a2fcdd1b9111b331941b32448a24f7dfe39c6f5703d9265be9",
"sha256": "ed77e46f46fba1fbee3d6679fdf828313d83ad5f62e74f374cff6f1d9c8accb0"
}
],
"package_integrity": [
{
"filename": "spoint-0.1.699.tgz",
"hashes": {
"sha1": "a24b8e6d9ecb4109510e5b7c3c9b1003f41d066f",
"sha512_sri": "sha512-+Szzx1MCLTm2RDv3pqEYxGWYw7AuzkMNgV3CffMMVfw7/MC8LczS+HC77qiTRe67Toj+u1+cSUXcFpfcOv+bJw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/spoint/MAL-2026-13725.json"