MAL-2026-16025

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bmc-i18n-extract-cli/MAL-2026-16025.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16025
Aliases
  • GHSA-327g-rcr8-hp3p
Published
2026-09-07T13:51:36Z
Modified
2026-09-08T20:45:08Z
Summary
Malicious code in bmc-i18n-extract-cli (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (70d52b44b46819aa61ff57d4863315b09f655a4fb5b5787843c2a24f85d9c6db)

The package's package.json declares a preinstall hook bun run index.js and lists the Bun runtime (bun ^1.3.13) as a dependency, causing an obfuscated ~500KB index.js to execute automatically on npm install under a non-Node runtime. index.js is packed with obfuscator.io (rotated string array _0x71ec) and additionally implements a custom PBKDF2/HMAC-derived cipher whose decrypt function is installed on globalThis; the fetch base URL and User-Agent are reconstructed at runtime from encoded string-array indices rather than appearing as plaintext literals. The payload calls the GitHub API with an Authorization Bearer token, inspects the X-OAuth-Scopes response header for repo and workflow scopes, and enumerates /user/orgs — token triage and org enumeration unrelated to the package's stated i18n/translation purpose. index.js is not listed in package.json's declared files array (bin, dist, types, README.md) yet ships at the tarball root and is referenced by the preinstall script, indicating the payload sits outside the author's declared publish surface.

Source: ghsa-malware (6567fe3822e10873e7be53d7b830f525aa2fc5efc3083c0fe2b713bd896220eb)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "GHSA-327g-rcr8-hp3p",
            "import_time":  "2026-09-08T00:15:09.871090224Z",
            "modified_time":  "2026-09-07T13:51:36Z",
            "ranges":  [
                {
                    "events":  [
                        {
                            "introduced":  "0"
                        }
                    ],
                    "type":  "SEMVER"
                }
            ],
            "sha256":  "6567fe3822e10873e7be53d7b830f525aa2fc5efc3083c0fe2b713bd896220eb",
            "source":  "ghsa-malware"
        },
        {
            "id":  "IN-MAL-2026-019713",
            "import_time":  "2026-09-08T20:38:59.341590696Z",
            "modified_time":  "2026-09-08T20:22:58Z",
            "sha256":  "70d52b44b46819aa61ff57d4863315b09f655a4fb5b5787843c2a24f85d9c6db",
            "source":  "amazon-inspector",
            "versions":  [
                "1.1.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / bmc-i18n-extract-cli

Package

Name
bmc-i18n-extract-cli
View open source insights on deps.dev
Purl
pkg:npm/bmc-i18n-extract-cli

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "97c2dfd58410d5d856cef9bd5808fa5ac9bafce646cbf1f425ce49010e523024",
            "tlsh":  "8851a910cda9de432ac0a298e9bd06466029a4134c64fc4937f1537e4f2c6ef31bdb5d"
        },
        {
            "path":  "index.js",
            "sha256":  "e37e3ddeeaaa9e0c4fdbcb829b4895a6521031c80053fc436625b61e6ee5b1a6",
            "tlsh":  "d5b4a31123d46960274b4fbb771bb5f2e88a09ee786d0c9fe124bc1066d9713fae8570"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bmc-i18n-extract-cli/MAL-2026-16025.json"