MAL-2026-17314

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-supply-npm-lib-4/MAL-2026-17314.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17314
Published
2026-09-30T01:47:02Z
Modified
2026-09-30T06:00:05Z
Summary
Malicious code in test-supply-npm-lib-4 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268)

package.json declares a dependency sourced from a git URL (git+https://git@github.com/agustedone/test-supply-npm-git-prepare-proof-4.git) pinned to commit 0abd2c55e475f12f58fb67ac487db4c1b00cf597, rather than from the npm registry. On npm install, npm clones that GitHub repository and runs any lifecycle scripts it contains, including a prepare hook indicated by the dependency's name. The dependency source is an individual GitHub account (agustedone/...) unrelated to any established publisher, and the fetched code is not subject to npm registry review or integrity checks against a registry tarball. Whoever controls that GitHub repository controls code executed on the installer's machine at install time.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020791",
            "import_time":  "2026-09-30T02:52:56.663772057Z",
            "modified_time":  "2026-09-30T01:47:10Z",
            "sha256":  "4088f6f05dc6a2187563d3b6e47047d7206446a8642bb62d2cc2c27347418e70",
            "source":  "amazon-inspector",
            "versions":  [
                "3.3.3"
            ]
        },
        {
            "id":  "IN-MAL-2026-020790",
            "import_time":  "2026-09-30T02:52:56.544764263Z",
            "modified_time":  "2026-09-30T01:47:02Z",
            "sha256":  "80bcbaa6379206627641c70dd25da3c3adfd51337f9a378223a6f8f13c8ba3ed",
            "source":  "amazon-inspector",
            "versions":  [
                "3.3.4"
            ]
        },
        {
            "id":  "IN-MAL-2026-020820",
            "import_time":  "2026-09-30T05:44:17.304955595Z",
            "modified_time":  "2026-09-30T05:30:46Z",
            "sha256":  "3eae72a7bc74450d855cd61f154508a7b6e1419095c8d3c88c32f3e81b77b3af",
            "source":  "amazon-inspector",
            "versions":  [
                "3.3.6"
            ]
        },
        {
            "id":  "IN-MAL-2026-020821",
            "import_time":  "2026-09-30T05:44:17.334402313Z",
            "modified_time":  "2026-09-30T05:30:56Z",
            "sha256":  "44f10381ad047460986bbeedafad42f8c71db61fff98fe07c915cd0d3678d268",
            "source":  "amazon-inspector",
            "versions":  [
                "3.3.5"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / test-supply-npm-lib-4

Package

Name
test-supply-npm-lib-4
View open source insights on deps.dev
Purl
pkg:npm/test-supply-npm-lib-4

Affected ranges

Affected versions

3.*
3.3.3
3.3.4
3.3.5
3.3.6

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "8d90884a76b25c576aecaa0b096d8c7c1d8d934e8c6ac6e11501bc18b6adfc06",
            "tlsh":  "48e05c60d6210c7728c129f0cc613443ff518c234464ad053793516dce491bb40fd63f"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "test-supply-npm-lib-4-3.3.3.tgz",
            "hashes":  {
                "sha1":  "e350fa83bf9607ab65feda3190e2d7d1bc4fd99e",
                "sha512_sri":  "sha512-BhsR8kcp0u4pNt6yZ/RiP46Xt2hUNuBZreE1lghxVuCLPV3+CNO1lbgVLlaM27uxYEC4evcfDdVjK4nP+5tGSA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test-supply-npm-lib-4/MAL-2026-17314.json"