MAL-2026-14036

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/notafollower1226/MAL-2026-14036.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14036
Published
2026-08-14T14:07:21Z
Modified
2026-08-14T14:46:37Z
Summary
Malicious code in notafollower1226 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (fdc72e98071e37ff58c3bb327f995c9c586b81a22180a8004b6564026cbc629f)

The package.json postinstall script auto-executes on npm install. It queries the ECS container metadata endpoint (ECS_CONTAINER_METADATA_URI_V4/task) to collect the Task ARN, container image list, and log group/stream configuration, then enumerates process.env for keys matching /owner|team|user|created|author|maintainer|contact/i, and pipes the resulting report via curl -X POST --data-binary @- to the hardcoded anonymous ngrok tunnel https://mourner-slot-explicit.ngrok-free.dev. The destination is not associated with any declared publisher and ngrok-free.dev subdomains are ephemeral anonymous tunnels typical of supply-chain reconnaissance against CI/build infrastructure. The package ships no other functionality consistent with a legitimate declared purpose; its only install-time effect is the exfiltration beacon.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-017763",
            "import_time": "2026-08-14T14:28:07.081685824Z",
            "modified_time": "2026-08-14T14:12:33Z",
            "sha256": "3bcf9577fe9f2f92d37e3ca5b59f9e44829debf5404254c759e2e98c3586a2a6",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-017729",
            "import_time": "2026-08-14T14:28:03.55331463Z",
            "modified_time": "2026-08-14T14:07:21Z",
            "sha256": "5952c329f4f236534541bd9473d97f380c4b6a3f6ae89c4024cb59e9b467ae58",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-017764",
            "import_time": "2026-08-14T14:28:07.187105602Z",
            "modified_time": "2026-08-14T14:12:41Z",
            "sha256": "664d1be72acf562df144f741b727bc66b65c1d740fee1c7c77f22e1af0abd679",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-017742",
            "import_time": "2026-08-14T14:28:04.881974478Z",
            "modified_time": "2026-08-14T14:09:20Z",
            "sha256": "6eee9700fa8aef87c54e74f243f093f510e29eddfdb5fdbfa369d31a435f9668",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-017778",
            "import_time": "2026-08-14T14:28:08.415609892Z",
            "modified_time": "2026-08-14T14:22:36Z",
            "sha256": "8b1450e0f0ed1fb1548ee13a13bd220e327cbd07f60fe1dd99e43e09f7dd2ff7",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-017744",
            "import_time": "2026-08-14T14:28:05.111256076Z",
            "modified_time": "2026-08-14T14:09:38Z",
            "sha256": "fdc72e98071e37ff58c3bb327f995c9c586b81a22180a8004b6564026cbc629f",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / notafollower1226

Package

Name
notafollower1226
View open source insights on deps.dev
Purl
pkg:npm/notafollower1226

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "6950161f4fd924e6e2fa1868e6b2f5fcce82c7b2094252b9d791ed8b5b89e7e0",
            "tlsh": "94016564ce4916b668ce8bcc59479253e562741bb910cdc8e6b42464cac3e87bc23319"
        }
    ],
    "package_integrity": [
        {
            "filename": "notafollower1226-1.0.3.tgz",
            "hashes": {
                "sha1": "3498d083afee410b3019692088040de57090d3de",
                "sha512_sri": "sha512-Un/ZzPbSgXYpiUf+f6nqfHiMEdwsyUpQpnR1HEmleASTVhGju8hQVK77SQ94lLHwxRep/8+Qdtgq2zMaKPR7Hg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/notafollower1226/MAL-2026-14036.json"