MAL-2026-17318

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/developmentstelemetry/MAL-2026-17318.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17318
Published
2026-09-30T03:06:03Z
Modified
2026-09-30T03:30:04Z
Summary
Malicious code in developmentstelemetry (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (98ef8863222571a8e77635ed5129c41ad9583d9df4e9e5fd61b5a07c4fb26887)

package.json declares scripts.postinstall = 'node index.js'. index.js is a 143-byte stub whose only behavior is to dynamically import the sole declared dependency 'originaldevelopmentstelemetry@1.2.2' and invoke its exported downloadAndRunUpdate() function. On every 'npm install', control is handed to that external package, which by name and by its own exported API downloads and runs an 'update' payload on the installer's machine. The shipped bytes are inert; the entire install-time effect lives in an unaudited third-party package whose author controls arbitrary code execution on installers. Package name 'developmentstelemetry' with a self-labeled 'Gets telemetry data' description and author 'originaldevelopment' matches the wrapper-that-only-calls-another-package shape used to funnel installs into a payload-bearing dependency.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020797",
            "import_time":  "2026-09-30T03:24:19.871141408Z",
            "modified_time":  "2026-09-30T03:06:03Z",
            "sha256":  "3263cf14c0493d4001045efe3a08f5058c63e5955d2d554d4b1f6bc92f13d442",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-020798",
            "import_time":  "2026-09-30T03:24:19.996807645Z",
            "modified_time":  "2026-09-30T03:06:23Z",
            "sha256":  "98ef8863222571a8e77635ed5129c41ad9583d9df4e9e5fd61b5a07c4fb26887",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / developmentstelemetry

Package

Name
developmentstelemetry
View open source insights on deps.dev
Purl
pkg:npm/developmentstelemetry

Affected ranges

Affected versions

1.*
1.0.1
1.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "9b871ebd0e8ebb6a743f22f3968652b1f1aba31fefaf4a853f12214010b1bb8c",
            "tlsh":  "cfc02b2ec23f8934f5347b38030f012000f3011219028cd034bc30c86020420f435ccf"
        },
        {
            "path":  "package.json",
            "sha256":  "4a98fec330f289d2febf73e3fa74e8cbb458cd66cccdbcfe6e1b8fd7017c26a8",
            "tlsh":  "eae0df384a20a923a4dc22b509b7458366e38e2b00087c5833eb115c93deab728fe10e"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "developmentstelemetry-1.0.2.tgz",
            "hashes":  {
                "sha1":  "af7205bef4a236dfdb2cbfc7a97498d07da669ee",
                "sha512_sri":  "sha512-YY91JjqvsYDhloc5bbplY5fGjvaR4N1qhvZXfp/OfEWqJKcJRhmIPgrDY7NR/qMHPnS7cZXIW1HX9O0U+lK8rw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/developmentstelemetry/MAL-2026-17318.json"