-= Per source details. Do not edit below this line.=-
package.json registers a bin entry named npm pointing at npm.js, deliberately colliding with the core npm CLI. Once this package is installed as a dependency, any npm... invocation in a consuming project's scripts resolves via node_modules/.bin to this shim, executing the shipped code before (or instead of) the real npm. npm.js contains a steal() routine that reads process.env.HOME, process.env.SECRET, and the first 30 bytes of ~/.ssh/known_hosts, concatenates them into a query string, and issues a fetch GET to http://localhost:1337/. The destination is loopback in this build, but the collected data (installer SSH known_hosts contents and environment secrets) is packaged into a functioning exfiltration primitive that fires whenever the shadow npm shim is invoked from the installer's build scripts. The scope name (@selfpentest) and README frame this as a demonstration, but the shipped tarball is a working bin-shadow + credential-read + network-send chain against installers who add it as a dependency.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020685",
"import_time": "2026-09-29T22:18:23.828093319Z",
"modified_time": "2026-09-29T22:12:09Z",
"sha256": "40a68543ca2674f2b90d89dd52516736791b7886d617c694d89dd3135e7499f3",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
},
{
"id": "IN-MAL-2026-020687",
"import_time": "2026-09-29T22:18:23.876033932Z",
"modified_time": "2026-09-29T22:12:27Z",
"sha256": "b8eee4f9fa3dd0a476be7853709b1d126d84b0cc51b9a298d822038cb7c05c80",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "package.json",
"sha256": "57e36195d9df49781c8fd45bf2f25f79950a80c0564fc2d90399397529b0c699",
"tlsh": "a0e0c2174e12246314e819651c39417bb52a8f6b285ebd652bffa20c92cd3bb643564c"
},
{
"path": "npm.js",
"sha256": "f82f3e8a084d7d4c833daf350c1ae17534841c6d540f138fe573a5dedfed572b",
"tlsh": "4a41004620f11a3886b222a3779b24033afbd0a73215cca475dc8671df5af758261dfa"
}
],
"package_integrity": [
{
"filename": "bin-confusion-1.0.1.tgz",
"hashes": {
"sha1": "7253b6b5cecfbdc5fec4eca9e304ed25f68bb86a",
"sha512_sri": "sha512-+jfVd+b1JHd8zttc8dXEdmFOoR2hmFLkQGXSmZwCDG7XdBr4d5W2adh6eOZJWZ8FTMr/A41pSA16ABSKLNxGZQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@selfpentest/bin-confusion/MAL-2026-17292.json"