MAL-2026-17502

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/botmaker-cli/MAL-2026-17502.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17502
Published
2026-10-04T23:17:21Z
Modified
2026-10-04T23:45:19Z
Summary
Malicious code in botmaker-cli (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa)

On npm install, postinstall.js collects the installer's hostname, username, current working directory, architecture, platform, and network interface list (including private IPs) and POSTs them as JSON to the hardcoded host telemetry-edge.net at /api/v1/telemetry over HTTPS with certificate validation disabled (rejectUnauthorized: false). The same postinstall script reads the HTTP response body, parses it as JSON, and passes the response's exec field to child_process.execSync with a 30-second timeout, granting whoever controls telemetry-edge.net arbitrary shell command execution as the installing user on every machine that runs npm install. The package's index.js is an inert stub containing only module.exports = { version: '0.1.19' } and a comment directing users to a different scoped package (@botmaker.org/botmaker-cli), indicating this unscoped name is a lookalike lure whose sole operative payload is the install-time beacon-and-exec channel.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020904",
            "import_time":  "2026-10-04T23:40:40.315999962Z",
            "modified_time":  "2026-10-04T23:17:21Z",
            "sha256":  "86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa",
            "source":  "amazon-inspector",
            "versions":  [
                "0.1.19"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / botmaker-cli

Package

Affected ranges

Affected versions

0.*
0.1.19

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "postinstall.js",
            "sha256":  "d58662b9c4fa3a7af9a2adb9484e90de88d32e6c34f87f8e60d02d2abd64f299",
            "tlsh":  "401132e116f1527096f7d4ee5917d41a6213d0177a0aede0b99c42246fcd43c60f2af6"
        },
        {
            "path":  "index.js",
            "sha256":  "99b6c35fbe4cc2f8b4a6f37f5c02ece9e55c1d93b29a3b9c202b1f2eae4bdc9c",
            "tlsh":  "2dc09b171e1f2b276956cf52a34f56442f545570246b4d9835d7950c874580d4505185"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "botmaker-cli-0.1.19.tgz",
            "hashes":  {
                "sha1":  "feb6eb6158732c49c32737a33e840bf140d02b8d",
                "sha512_sri":  "sha512-Lfb0zjFkmqHO4JI2oLe7MeIyrAgdueGqm4p0BxozJl6eTNYOVWfoDN7uzcpKwI8IgCfAKTiqwi38s7OUtAqEbw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/botmaker-cli/MAL-2026-17502.json"