MAL-2026-16252

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ragacateslikodi/MAL-2026-16252.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16252
Published
2026-09-17T14:29:34Z
Modified
2026-09-17T14:45:11Z
Summary
Malicious code in ragacateslikodi (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (09a5a8774b4ce673a050b7e26c7d08aec66320fc14257196157363935ac19aa1)

On require/import of the package's main entry, a top-level async IIFE probes http://localhost:5000 for a hardcoded set of paths (/admin, /flag, /profile variants), concatenates status, length, and any body content matching flag patterns from those responses, and POSTs the aggregated result to a hardcoded webhook.site endpoint (https://webhook.site/1895d1d5-b227-4ce4-a2ce-232b1bec8b65). Package metadata is empty (no description, author, or repository), and the package ships no legitimate functionality alongside this behavior. Installing and importing this package causes any locally accessible service on port 5000 — including internal admin interfaces or CTF-style flag endpoints — to be scraped and its responses sent to an attacker-controlled collector.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020125",
            "import_time":  "2026-09-17T14:41:23.897774648Z",
            "modified_time":  "2026-09-17T14:29:43Z",
            "sha256":  "09a5a8774b4ce673a050b7e26c7d08aec66320fc14257196157363935ac19aa1",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.6"
            ]
        },
        {
            "id":  "IN-MAL-2026-020130",
            "import_time":  "2026-09-17T14:41:24.095115617Z",
            "modified_time":  "2026-09-17T14:30:42Z",
            "sha256":  "be3da2d46d7ccf5ba3c5b6d60ad5c1dd017e217e59a93dbe4dd9ab5b603c46a0",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.4"
            ]
        },
        {
            "id":  "IN-MAL-2026-020129",
            "import_time":  "2026-09-17T14:41:24.060546148Z",
            "modified_time":  "2026-09-17T14:30:29Z",
            "sha256":  "ea6e2daaaa29569b0b4795a001fcbe3bf2bbc0bdc0b7338ee82138abbb3c957b",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.3"
            ]
        },
        {
            "id":  "IN-MAL-2026-020124",
            "import_time":  "2026-09-17T14:41:23.836007304Z",
            "modified_time":  "2026-09-17T14:29:34Z",
            "sha256":  "f8ad4225427b8fe57302074a4267901541ba35bc738e626397c7d0786dd5b080",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.5"
            ]
        },
        {
            "id":  "IN-MAL-2026-020126",
            "import_time":  "2026-09-17T14:41:23.930408405Z",
            "modified_time":  "2026-09-17T14:29:51Z",
            "sha256":  "71f3126e7c743f499defbb81e43d5e10a8af0073e74b8595159d764e09b98e91",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020128",
            "import_time":  "2026-09-17T14:41:23.997237064Z",
            "modified_time":  "2026-09-17T14:30:12Z",
            "sha256":  "a0005e757d120bc269a995c4c210f4ba96b5e5193ae23b4b7dab6957daf8c66a",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020127",
            "import_time":  "2026-09-17T14:41:23.968581453Z",
            "modified_time":  "2026-09-17T14:30:02Z",
            "sha256":  "bac0bb870ba07bff9e74dbe646f30aab7cce037e799cd0f7d8f88c9aed2fa1a8",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / ragacateslikodi

Package

Name
ragacateslikodi
View open source insights on deps.dev
Purl
pkg:npm/ragacateslikodi

Affected ranges

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "beaf8b4fd27dbf854e750648e488a59b8bceee6cb7755f7c67ba4ee17d7209bc",
            "tlsh":  "a711bd7f886e245a0495f9c532e6a821cf03a42d79718d5bbf0c4a2d1fc780c5cd23b6"
        },
        {
            "path":  "package.json",
            "sha256":  "570003a68235a376903d112f43e2bc8e911acd832ed4cc761be0fac76cdaae04",
            "tlsh":  "60d0a7281a72543315c012220e6aa052b760df6f00447c0c57cf582c92dfab35cfd35d"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "ragacateslikodi-1.0.6.tgz",
            "hashes":  {
                "sha1":  "3be53e586f6e8ec99f1a1a219303b5de58e77774",
                "sha512_sri":  "sha512-GGQtu2RDEtrto+v8lhBw/Qy5+NcwGoCVkKbiFoVD4RZTEBsEKP4fBIsxYGbKc5wkONtTF+8k5kufYyZFLjTjEA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ragacateslikodi/MAL-2026-16252.json"