MAL-2026-17515

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/monitoring-agent/MAL-2026-17515.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17515
Published
2026-10-04T23:26:54Z
Modified
2026-10-04T23:45:16Z
Summary
Malicious code in monitoring-agent (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (703c1e796904571c9f0d08a4769a5f7e25a646483b4a66815a6ddc420ae0ecee)

The package exports an Express middleware (monitor()) advertised as a monitoring tool. On every response finish, the middleware POSTs the inbound HTTP request to a hardcoded author-controlled host at https://backend-cybersecuritydashboard.onrender.com/api/events. The payload explicitly extracts req.body.password, req.body.username, and req.body.email as dedicated fields alongside the full request headers, body, query string, and route params. The destination URL is not configurable by the caller — the only caller-supplied value is an apiKey. Any Express application that mounts this middleware will silently forward its end users' plaintext credentials and complete request payloads to this third-party Render host on every request. The package.json uses placeholder author metadata (Your Name) with no repository or homepage, and the exfiltration destination is unrelated to any disclosed publisher.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020963",
            "import_time":  "2026-10-04T23:40:46.361161141Z",
            "modified_time":  "2026-10-04T23:26:54Z",
            "sha256":  "703c1e796904571c9f0d08a4769a5f7e25a646483b4a66815a6ddc420ae0ecee",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / monitoring-agent

Package

Name
monitoring-agent
View open source insights on deps.dev
Purl
pkg:npm/monitoring-agent

Affected ranges

Affected versions

1.*
1.0.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "monitor.js",
            "sha256":  "4457e192153bd97382a9656f01ee8e3a8cab4105c583b7b88a42016d70784d5a",
            "tlsh":  "0c21bd1f4583105405bae7a88661491de222c727d90e8d12be7c857d4fbc00160c5fec"
        },
        {
            "path":  "package.json",
            "sha256":  "a0722ffac099d2a117fd72c7505c3c7bec5ecd9cd9e04abfc7e80f5bf6f1d475",
            "tlsh":  "5af09720c2205a2b03d935681d955143b6a28e8b12647d0873cf623c4bcf03f3afe22c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "monitoring-agent-1.0.1.tgz",
            "hashes":  {
                "sha1":  "f0555042009d4f3708fd80859b7d39ab95f91e82",
                "sha512_sri":  "sha512-NJOemjl/hq2ehMts1chz2YsuDr4O37FhNYQprI6QFB+JuZs2+9FYWFHA6/7xFjqSlm5+a/bGAvh5D1uD7y3kKg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/monitoring-agent/MAL-2026-17515.json"