MAL-2026-16117

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-cashout/MAL-2026-16117.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16117
Published
2026-09-10T04:45:58Z
Modified
2026-09-11T18:45:05Z
Summary
Malicious code in etoro-cashout (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1)

The package's preinstall.js lifecycle script runs on npm install and executes host reconnaissance commands (whoami, ipconfig/ip addr, directory listings of C:\ and /, tasklist/ps, and a full environment-variable dump via set/env) and POSTs the collected output over plain HTTP to a hardcoded remote server at 209.126.81.147, using path segments under a canary token 'etoro-nuget-verify1f8eaa57a875'. The package name 'etoro-cashout' at version 99.0.2, the eToro-branded canary, and the beacon path shape are consistent with a dependency-confusion probe targeting an internal eToro registry: any build environment that resolves this public name executes the exfiltration on install. Data leaving the installer includes hostname, username, working directory, filesystem listings, running processes, and the full process environment, which on CI systems routinely contains cloud credentials, registry tokens, and API keys.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-019915",
            "import_time":  "2026-09-10T05:18:06.257486475Z",
            "modified_time":  "2026-09-10T04:45:58Z",
            "sha256":  "a35bbd75e3cc742fd88d59bcbb64858df0474505b5d6f93f10e8c727c718e129",
            "source":  "amazon-inspector",
            "versions":  [
                "999.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-019996",
            "import_time":  "2026-09-11T18:21:31.906581633Z",
            "modified_time":  "2026-09-11T17:55:21Z",
            "sha256":  "a0d8b123f09da5d5d7e0c5f90590e52f5a02d5f1da0b52b4eb5cebd7ecb28071",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-019997",
            "import_time":  "2026-09-11T18:21:31.965819313Z",
            "modified_time":  "2026-09-11T17:55:29Z",
            "sha256":  "c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / etoro-cashout

Package

Name
etoro-cashout
View open source insights on deps.dev
Purl
pkg:npm/etoro-cashout

Affected ranges

Affected versions

99.*
99.0.0
99.0.2
999.*
999.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "preinstall.js",
            "sha256":  "bee47062733940943fd3a66654f0258135fd62911674304ccac11a43226b5f58",
            "tlsh":  "ebe027f4118ca6683ccc01c4636b191ed4dfc705bcdec8c04a55d78587b15f1d6115f0"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "etoro-cashout-999.0.0.tgz",
            "hashes":  {
                "sha1":  "6be0db8f77a1da1981745fd01e3519c5b6de0965",
                "sha512_sri":  "sha512-+oObK225egLxDtxuG7nwvQMvj7+AiKoi7cMQ1rVzqXSNbFE2uQFDFClsPw6xPt/GpoVCnWUT3t/jwft9Nw80sA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-cashout/MAL-2026-16117.json"