MAL-2026-17498

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@kibt/www-nuxt-i18n/MAL-2026-17498.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17498
Published
2026-10-04T23:18:25Z
Modified
2026-10-04T23:45:17Z
Summary
Malicious code in @kibt/www-nuxt-i18n (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5ab1895c73507311b9efd31e40015529d9d7735c87e50cf3b714e6e520205ec4)

The package is a stub whose index.js exports a Proxy returning no-op functions for every property access, allowing bundlers that import any member of the expected real package to succeed. The package.json declares a postinstall script node beacon.cjs, and index.js also loads the same beacon at require() time. beacon.cjs collects installer host metadata — os.hostname(), the install directory (__dirname), process.cwd(), and process.version — and POSTs it to the hardcoded plain-HTTP bare-IP endpoint http://185.158.107.175:8787/_ah/dc. The destination is not affiliated with any legitimate publisher, the package provides no real functionality, and an in-source comment frames successful installs as evidence of a hit — matching the canonical dependency-confusion / namesquat validator shape where host identity is reported back to the operator to confirm which internal environments resolved the attacker-controlled scoped name.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020917",
            "import_time":  "2026-10-04T23:40:41.723166935Z",
            "modified_time":  "2026-10-04T23:19:22Z",
            "sha256":  "485839cc6750a2751283c1a9453c7b28bf58a29ca316cdb5c4e3027afc2e731b",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020915",
            "import_time":  "2026-10-04T23:40:41.516929707Z",
            "modified_time":  "2026-10-04T23:19:05Z",
            "sha256":  "ec95d08e30fac283e7a552bcf9bd48a3d3059a6c92ea5f6b846ed1bd3dccc402",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020911",
            "import_time":  "2026-10-04T23:40:41.138097956Z",
            "modified_time":  "2026-10-04T23:18:25Z",
            "sha256":  "f85cda0eb18d988d0bc6c5f066f764e86756851f34449942c7ca858a46b22577",
            "source":  "amazon-inspector",
            "versions":  [
                "0.1.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020912",
            "import_time":  "2026-10-04T23:40:41.231560328Z",
            "modified_time":  "2026-10-04T23:18:34Z",
            "sha256":  "5ab1895c73507311b9efd31e40015529d9d7735c87e50cf3b714e6e520205ec4",
            "source":  "amazon-inspector",
            "versions":  [
                "0.0.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020913",
            "import_time":  "2026-10-04T23:40:41.327549809Z",
            "modified_time":  "2026-10-04T23:18:43Z",
            "sha256":  "98b7faf73b0fb9d003258f882b09b23728db415cdf504436021d32f6ac791a29",
            "source":  "amazon-inspector",
            "versions":  [
                "1.1.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020914",
            "import_time":  "2026-10-04T23:40:41.424700819Z",
            "modified_time":  "2026-10-04T23:18:56Z",
            "sha256":  "c3dd2ab4972bdf73b521c63a38dd410378d0ad84f6485ededddd423e19e4ac7f",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        },
        {
            "id":  "IN-MAL-2026-020919",
            "import_time":  "2026-10-04T23:40:41.932811285Z",
            "modified_time":  "2026-10-04T23:19:44Z",
            "sha256":  "cf82f32b9ae316d7d4931838da5479339785b611adc42d220bd65feca5bdd8ee",
            "source":  "amazon-inspector",
            "versions":  [
                "3.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020916",
            "import_time":  "2026-10-04T23:40:41.612444927Z",
            "modified_time":  "2026-10-04T23:19:15Z",
            "sha256":  "d89b7fb5a53b101194ba86edae564e7cbd573f51001004f536e8b1e6a2d98962",
            "source":  "amazon-inspector",
            "versions":  [
                "2.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @kibt/www-nuxt-i18n

Package

Name
@kibt/www-nuxt-i18n
View open source insights on deps.dev
Purl
pkg:npm/%40kibt/www-nuxt-i18n

Affected ranges

Affected versions

0.*
0.0.1
0.1.0
1.*
1.0.0
1.0.1
1.1.0
2.*
2.0.1
3.*
3.0.0
99.*
99.0.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "beacon.cjs",
            "sha256":  "029af10dabcfa3ab85da4ce16ad46e6b67aef25ad5f7cee8615f0387379e5a3b",
            "tlsh":  "d9316feba8f1a008aaaa7498c54f0409f27bf0068401af54f95c82919f6193c33fa8dc"
        },
        {
            "path":  "package.json",
            "sha256":  "cb48910951c419b943131d8a4ab0cd62d1e7bb54141356426318d8fef287a2aa",
            "tlsh":  "e0d02e20ca201e2324c82ee20e2a2a0a65a20d2b01043c083387402c06acb3728ff23f"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "www-nuxt-i18n-99.0.1.tgz",
            "hashes":  {
                "sha1":  "71cdd733dc6440b86bf6f5d772b30a93332b5f25",
                "sha512_sri":  "sha512-QyK3xbP2bFLNT+7CcVEoSlR6BBbCd8DNrgez0PLfkNHI0TUp8oIP6842KscQtk7/bI1mTibg+Z65X1pQ7+aNmQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@kibt/www-nuxt-i18n/MAL-2026-17498.json"