-= Per source details. Do not edit below this line.=-
canary.js in zeal-utils@0.0.0 collects host reconnaissance data (os.hostname(), os.userInfo(), process.platform, cwd, node version) and POSTs it to the hardcoded external endpoint https://npm-canary.aveliscare.com. The destination is not a package registry or documented vendor endpoint and is unrelated to any legitimate utility functionality implied by the package name. The package name and near-empty version (0.0.0) combined with a single script that beacons system identification to an author-controlled host is consistent with a dependency-confusion or canary-token style beacon that identifies internal build environments where the package resolves.
{
"malicious-packages-origins": [
{
"id": "RLMA-2026-10816",
"import_time": "2026-09-24T09:21:36.788333765Z",
"modified_time": "2026-09-22T17:46:49Z",
"sha256": "9f91f6dc4415c8175df7186c2a51dfb42c82b7a9a7272b370d398ea0cc2d063c",
"source": "reversing-labs",
"versions": [
"0.0.0"
]
},
{
"id": "IN-MAL-2026-020746",
"import_time": "2026-09-30T00:52:54.254341365Z",
"modified_time": "2026-09-30T00:31:23Z",
"sha256": "f7a4b9b4fcb0a48aa3602fc7bc865eff738f8ab42a4c9e56ea31e70b0b6b826f",
"source": "amazon-inspector",
"versions": [
"0.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "canary.js",
"sha256": "313f6afebeb44640d7df7a1995d0958bed918ecf2be8f171d4fbfe8dcab91f1d",
"tlsh": "acd1d86613f052762b8206b4591f00979736e027722aa170f5af92143f4a6bc87f3deb"
}
],
"package_integrity": [
{
"filename": "zeal-utils-0.0.0.tgz",
"hashes": {
"sha1": "e1c8208ac4a05ec633c74e2cd0197abf13732de9",
"sha512_sri": "sha512-DpDEt0CoOQ+i1WBRgIKh2MWqMZ4u5U5k/LKGHPwVeLH+HntYbIHkRVdC5pFLNyioh83HxrYGH45twtw6Z2TJvw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zeal-utils/MAL-2026-16542.json"