MAL-2026-15687

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@yuva2210/okx-poc-rce-impact/MAL-2026-15687.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-15687
Published
2026-08-24T16:34:29Z
Modified
2026-09-04T01:00:06Z
Summary
Malicious code in @yuva2210/okx-poc-rce-impact (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1917fdda46d566300463afdd1087755e9cf50203f4997455f9ee888e01782124)

@yuva2210/okx-poc-rce-impact@2.0.0 is a dependency-confusion proof-of-concept targeting OKX's internal namespace. The package's package.json declares a preinstall script that runs on npm install and executes child_process.execSync calls for whoami, hostname, pwd, and id, collecting installer host and user identifiers and writing them to /tmp/okx-poc-rce-proof.json. The package has no other functional content — index.js is empty — so the tarball's only effect on installation is to execute the reconnaissance payload on the installer's machine. Any developer or build system that inadvertently resolves an OKX-internal name to this public package runs arbitrary code at install time. The self-labeled 'harmless PoC' framing does not change the mechanism: unsolicited command execution and host-identifier collection fire automatically on npm install.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "RLMA-2026-05949",
            "import_time":  "2026-09-01T11:17:26.679648626Z",
            "modified_time":  "2026-08-24T16:34:29Z",
            "sha256":  "a3b3b9c183ebf6f54dc431b511528972beb71ad492e38595ec816edc05041b7f",
            "source":  "reversing-labs",
            "versions":  [
                "2.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-019392",
            "import_time":  "2026-09-04T00:45:55.301292249Z",
            "modified_time":  "2026-09-03T23:51:18Z",
            "sha256":  "1917fdda46d566300463afdd1087755e9cf50203f4997455f9ee888e01782124",
            "source":  "amazon-inspector",
            "versions":  [
                "2.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @yuva2210/okx-poc-rce-impact

Package

Name
@yuva2210/okx-poc-rce-impact
View open source insights on deps.dev
Purl
pkg:npm/%40yuva2210/okx-poc-rce-impact

Affected ranges

Affected versions

2.*
2.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "d3f1f932f67970bfcb5c94e8e2857e3b51eabc366a7d6f2ffe81a236cb2feafe",
            "tlsh":  "232129125fc5efb92891d8421839c15bf912df0c205b6a5df4ae9277a2a8986232dd3c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "okx-poc-rce-impact-2.0.0.tgz",
            "hashes":  {
                "sha1":  "47a3971c7c810d82520fcec2a242f5de1fda62bf",
                "sha512_sri":  "sha512-9gEUvBH6RnAcLdNEy2oCCZg5YbAhQ7wmRycYPNNpfjdV81ZvD5IJk5DDyVbSxEhCYlLlh3c/pEQJCakNDjPfzA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@yuva2210/okx-poc-rce-impact/MAL-2026-15687.json"