-= Per source details. Do not edit below this line.=-
Package ships no legitimate functionality: package.json declares main=index.js which is absent from the tarball, and the only shipped source is main.js, which runs from a postinstall hook (node main.js) during npm install. main.js collects host identifiers via require('os') — os.hostname(), os.userInfo(), os.platform(), os.arch(), process.cwd(), process.version — and POSTs them as JSON over https to the hardcoded collector URL https://webhook.site/13d98b4a-1999-4ec7-92c9-0697c259ca05. The declared purpose (SQL limit enforcer) is a cover; the artifact is an install-time reconnaissance beacon.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020033",
"import_time": "2026-09-14T17:15:21.630521619Z",
"modified_time": "2026-09-14T16:52:54Z",
"sha256": "6f8126bab8131e5781af023537f7c5fc2456929c104f71312eeddcea358b5659",
"source": "amazon-inspector",
"versions": [
"10.0.0"
]
},
{
"id": "IN-MAL-2026-020135",
"import_time": "2026-09-17T17:15:41.6774283Z",
"modified_time": "2026-09-17T16:44:06Z",
"sha256": "4f9ee5879afaf071199fdaeea72cc8b534124c6c58a92181d6e91268ffe46338",
"source": "amazon-inspector",
"versions": [
"10.0.1"
]
},
{
"id": "IN-MAL-2026-020136",
"import_time": "2026-09-17T17:15:41.738530812Z",
"modified_time": "2026-09-17T16:44:17Z",
"sha256": "c14f49a581a7890694db81da8858fab6aa53bf91d45386ce26ca922118239ba6",
"source": "amazon-inspector",
"versions": [
"10.0.2"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "main.js",
"sha256": "241dea14d016fdb01c8e250eb2fa340e3bcb7cdb9248872c3b0f9fb239c44804",
"tlsh": "2301dce065f4a4610aa2bee42407e829a296e4177d06f880fe2c42981fdd92c58b2d69"
},
{
"path": "package.json",
"sha256": "0d3ae0c30e22a973958094ab1c109fecb9f8a7690aca8312789ae9a7b09e2c63",
"tlsh": "22d02e245a610a332ac4061a1c2aa042a270cf2f2408380893cb193cc9de2335cfb30e"
}
],
"package_integrity": [
{
"filename": "sql-limit-enforcer-10.0.0.tgz",
"hashes": {
"sha1": "6b7530eda0a10fc8d6ececb6ad77a09f3ef0007e",
"sha512_sri": "sha512-BUgT6oX3dFXMuVNHzKjE7ZJ4sprnVSnmr+YmJgYew//RmV0tWx30E4eRh8yA4NU1GcWewO62+G9tqbQB6nOHvQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/sql-limit-enforcer/MAL-2026-16151.json"