MAL-2026-14061

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hunterone-build-probe-9210/MAL-2026-14061.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14061
Published
2026-08-15T15:55:53Z
Modified
2026-08-15T16:15:13.855100359Z
Summary
Malicious code in hunterone-build-probe-9210 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3f27c0ce93b98a1c9d602604eef2a625c6a7c2ebb7a1be38eeeaf06deb4e436e)

probe.js runs automatically via package.json preinstall and postinstall hooks ("node probe.js || true"). On execution it collects os.hostname(), os.platform(), os.networkInterfaces(), cwd, uid, the output of id, a full process.env dump, /proc/self/environ, a root filesystem listing, and the contents of ~/.npmrc, and specifically reads AWSCONTAINERCREDENTIALSRELATIVEURI. The collected JSON payload is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/22508080-b099-4ec3-8ab7-7354af2886a9/buildenv. ~/.npmrc contains the installer's npm registry auth token, and the AWS ECS credential-endpoint variable exposes the path to fetch task-role AWS credentials; both are installer-owned secrets shipped to an anonymous third-party collector at install time.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-017952",
            "import_time": "2026-08-15T16:07:56.067589797Z",
            "sha256": "3ec98af6daa0ac779e19b9249ebfc0674e6b00926be73418af8568cf3ceb990c",
            "modified_time": "2026-08-15T15:56:33Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "import_time": "2026-08-15T16:07:55.781705387Z",
            "id": "IN-MAL-2026-017948",
            "sha256": "e9836b18137c6fbd69c9649ea8bf98c1d6f775d29862b622ba71b4284dbc1c2a",
            "modified_time": "2026-08-15T15:56:01Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "id": "IN-MAL-2026-017954",
            "import_time": "2026-08-15T16:07:56.230445531Z",
            "sha256": "f0a052c2ffbfbf2c3cb34252e725758a50453abe83d6c7584bf5d137da8a5b36",
            "versions": [
                "1.0.6"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-15T15:56:51Z"
        },
        {
            "id": "IN-MAL-2026-017947",
            "import_time": "2026-08-15T16:07:55.722887652Z",
            "sha256": "f9c474b248e3deb3b54338ed3e99a3922c225662bee7f969d0edc75ece636658",
            "modified_time": "2026-08-15T15:55:53Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-017951",
            "import_time": "2026-08-15T16:07:56.009203041Z",
            "sha256": "3f27c0ce93b98a1c9d602604eef2a625c6a7c2ebb7a1be38eeeaf06deb4e436e",
            "versions": [
                "1.0.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-08-15T15:56:24Z"
        },
        {
            "import_time": "2026-08-15T16:07:56.137223475Z",
            "id": "IN-MAL-2026-017953",
            "sha256": "4593a430d31b1354262bb20224ddcc167d2b274630a254f3cd6e656f7091ef10",
            "modified_time": "2026-08-15T15:56:43Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-017950",
            "import_time": "2026-08-15T16:07:55.953565043Z",
            "sha256": "578145e9754ef9bd5b0ec9f89d6de4a30d76c77ef8a92a91a8dc88b128583388",
            "modified_time": "2026-08-15T15:56:17Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-017949",
            "import_time": "2026-08-15T16:07:55.843135803Z",
            "sha256": "ae782a832d1741014f48e5944b8b6746ab02eb030b27e67dac2458ab3e6ba9ad",
            "modified_time": "2026-08-15T15:56:08Z",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / hunterone-build-probe-9210

Package

Name
hunterone-build-probe-9210
View open source insights on deps.dev
Purl
pkg:npm/hunterone-build-probe-9210

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "probe.js",
            "tlsh": "223193d025e262705f5013bdc82a6754f223e548720fad82f5ec69ce384b02cd3bf164",
            "sha256": "9a33397d7dba6a47596ad44e2c82e72b96b1cc9bfc98ade7772c34ede9b406cc"
        }
    ],
    "package_integrity": [
        {
            "filename": "hunterone-build-probe-9210-1.0.5.tgz",
            "hashes": {
                "sha512_sri": "sha512-5agEkqnyer6TnOOipTi7kxC+IJuKre3bIAJWKtwrKWhP9dkLZ7pjNCO1BN/2pve58C4ecOUomaR6XFOuxLDs/w==",
                "sha1": "587109379cb04ee5553d330cf9d0a7e61a947457"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/hunterone-build-probe-9210/MAL-2026-14061.json"