MAL-2026-13970

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hzero-front-ui/hzero-ui/MAL-2026-13970.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13970
Published
2026-08-13T21:06:51Z
Modified
2026-08-13T21:30:25.957644672Z
Summary
Malicious code in @hzero-front-ui/hzero-ui (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a1b33c04eb2fb12d521b76353993517475d9239c9790c085d16c0c3d0a4ba2f9)

Package @hzero-front-ui/hzero-ui@99.99.99 is a scope-lookalike of @hzero-front/hzero-ui with a placeholder version, empty author, generic description, and a trivial index.js. Its package.json preinstall and install lifecycle scripts base64-encode $(whoami):$(hostname):$(pwd):$npmpackagename and send the encoded value to attacker-controlled subdomains of callback.m0chan.co.uk over both HTTPS (curl) and DNS (nslookup). This fires automatically on npm install, leaking the installer's OS username, hostname, current working directory, and the internal package name that resolved to this lure — the canonical dependency-confusion beacon shape.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-017673",
            "import_time": "2026-08-13T21:20:57.017177222Z",
            "sha256": "a1b33c04eb2fb12d521b76353993517475d9239c9790c085d16c0c3d0a4ba2f9",
            "modified_time": "2026-08-13T21:06:51Z",
            "source": "amazon-inspector",
            "versions": [
                "99.99.99"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @hzero-front-ui/hzero-ui

Package

Name
@hzero-front-ui/hzero-ui
View open source insights on deps.dev
Purl
pkg:npm/%40hzero-front-ui/hzero-ui

Affected ranges

Affected versions

99.*
99.99.99

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "tlsh": "bc117a2541319eb6a9e24fb01c00aa2d65fdabaf317ebb49620e4a1f001d16171af64f",
            "sha256": "fcd4c5dcbab4d2bd11867f5c9be10dedb6cfb073a43b9e91d18557c94c2d8bc1"
        }
    ],
    "package_integrity": [
        {
            "filename": "hzero-ui-99.99.99.tgz",
            "hashes": {
                "sha512_sri": "sha512-M6UeOFs8ueM7H7Vpw4l2b5AzH7WZTPFXniLDf2FcInaAT5Qmbyq7kmM/WdV682BeRtsPGXfMNFyjRnf9wjZZfA==",
                "sha1": "73e292a995d25e0ad20b2c85f3f9eff14e3b5fbd"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@hzero-front-ui/hzero-ui/MAL-2026-13970.json"