MAL-2026-16542

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zeal-utils/MAL-2026-16542.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16542
Published
2026-09-22T17:46:49Z
Modified
2026-09-30T01:00:07Z
Summary
Malicious code in zeal-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f7a4b9b4fcb0a48aa3602fc7bc865eff738f8ab42a4c9e56ea31e70b0b6b826f)

canary.js in zeal-utils@0.0.0 collects host reconnaissance data (os.hostname(), os.userInfo(), process.platform, cwd, node version) and POSTs it to the hardcoded external endpoint https://npm-canary.aveliscare.com. The destination is not a package registry or documented vendor endpoint and is unrelated to any legitimate utility functionality implied by the package name. The package name and near-empty version (0.0.0) combined with a single script that beacons system identification to an author-controlled host is consistent with a dependency-confusion or canary-token style beacon that identifies internal build environments where the package resolves.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "RLMA-2026-10816",
            "import_time":  "2026-09-24T09:21:36.788333765Z",
            "modified_time":  "2026-09-22T17:46:49Z",
            "sha256":  "9f91f6dc4415c8175df7186c2a51dfb42c82b7a9a7272b370d398ea0cc2d063c",
            "source":  "reversing-labs",
            "versions":  [
                "0.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020746",
            "import_time":  "2026-09-30T00:52:54.254341365Z",
            "modified_time":  "2026-09-30T00:31:23Z",
            "sha256":  "f7a4b9b4fcb0a48aa3602fc7bc865eff738f8ab42a4c9e56ea31e70b0b6b826f",
            "source":  "amazon-inspector",
            "versions":  [
                "0.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / zeal-utils

Package

Affected ranges

Affected versions

0.*
0.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "canary.js",
            "sha256":  "313f6afebeb44640d7df7a1995d0958bed918ecf2be8f171d4fbfe8dcab91f1d",
            "tlsh":  "acd1d86613f052762b8206b4591f00979736e027722aa170f5af92143f4a6bc87f3deb"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "zeal-utils-0.0.0.tgz",
            "hashes":  {
                "sha1":  "e1c8208ac4a05ec633c74e2cd0197abf13732de9",
                "sha512_sri":  "sha512-DpDEt0CoOQ+i1WBRgIKh2MWqMZ4u5U5k/LKGHPwVeLH+HntYbIHkRVdC5pFLNyioh83HxrYGH45twtw6Z2TJvw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zeal-utils/MAL-2026-16542.json"