MAL-2026-14203

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@lilsccott6x9/devpipe-connector/MAL-2026-14203.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-14203
Published
2026-08-19T02:41:24Z
Modified
2026-08-19T03:00:12.726383219Z
Summary
Malicious code in @lilsccott6x9/devpipe-connector (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e8615ec2381e2fc36518a5f991f1a132ffe8c86fc458a7072585bb950644eb1f)

The package's postinstall lifecycle hook (package.json declares postinstall=node scripts/setup.js) decodes base64-encoded shell command strings and executes them via child_process.execSync. The setup.js script stores payloads as base64 literals in an object (_m.w for Windows, _m.p for POSIX), decodes them at runtime with Buffer.from(s,'base64').toString('utf8'), branches on os.platform(), and dispatches to execSync with shell 'cmd.exe' on Windows or the default shell on Unix. The decoded commands write a 'WebMCP-RCE-CANARY' / pwned.txt file to the installer's Desktop, demonstrating arbitrary command execution on both Windows and Unix hosts at every npm install. Obfuscating shell strings as base64 in a lifecycle script has no legitimate purpose in a package presenting itself as a CI/CD connector SDK; the mechanism is a general-purpose install-time RCE primitive and the current canary payload is a proof of execution rather than a functional install step.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-19T02:57:21.398214293Z",
            "sha256": "e8615ec2381e2fc36518a5f991f1a132ffe8c86fc458a7072585bb950644eb1f",
            "modified_time": "2026-08-19T02:41:24Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-018294",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @lilsccott6x9/devpipe-connector

Package

Name
@lilsccott6x9/devpipe-connector
View open source insights on deps.dev
Purl
pkg:npm/%40lilsccott6x9/devpipe-connector

Affected ranges

Affected versions

1.*
1.0.0

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@lilsccott6x9/devpipe-connector/MAL-2026-14203.json"
indicators
{
    "evidence_files": [
        {
            "sha256": "28b05926e2738886530de5221c1b3519686e662420942e42d547f62eb930d268",
            "tlsh": "6101fed819f0b93637fd75d0c42678ddb2ebea1034d8b6e04dbe909c5711aa04a731e6",
            "path": "scripts/setup.js"
        }
    ],
    "package_integrity": [
        {
            "filename": "devpipe-connector-1.0.0.tgz",
            "hashes": {
                "sha512_sri": "sha512-sC439pvh7aUASmddtQrduYzPZNy0YkWf8zgCKnlGXoShj1TB4SPjKf/LLjUMAM7NM3KKFUeKycTfrBqIJVtWhQ==",
                "sha1": "f2f2d8ab636ad7df25316b641de4ba4a444149b2"
            }
        }
    ]
}
cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]