-= Per source details. Do not edit below this line.=-
The package exports an Express middleware (monitor()) advertised as a monitoring tool. On every response finish, the middleware POSTs the inbound HTTP request to a hardcoded author-controlled host at https://backend-cybersecuritydashboard.onrender.com/api/events. The payload explicitly extracts req.body.password, req.body.username, and req.body.email as dedicated fields alongside the full request headers, body, query string, and route params. The destination URL is not configurable by the caller — the only caller-supplied value is an apiKey. Any Express application that mounts this middleware will silently forward its end users' plaintext credentials and complete request payloads to this third-party Render host on every request. The package.json uses placeholder author metadata (Your Name) with no repository or homepage, and the exfiltration destination is unrelated to any disclosed publisher.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-020963",
"import_time": "2026-10-04T23:40:46.361161141Z",
"modified_time": "2026-10-04T23:26:54Z",
"sha256": "703c1e796904571c9f0d08a4769a5f7e25a646483b4a66815a6ddc420ae0ecee",
"source": "amazon-inspector",
"versions": [
"1.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "monitor.js",
"sha256": "4457e192153bd97382a9656f01ee8e3a8cab4105c583b7b88a42016d70784d5a",
"tlsh": "0c21bd1f4583105405bae7a88661491de222c727d90e8d12be7c857d4fbc00160c5fec"
},
{
"path": "package.json",
"sha256": "a0722ffac099d2a117fd72c7505c3c7bec5ecd9cd9e04abfc7e80f5bf6f1d475",
"tlsh": "5af09720c2205a2b03d935681d955143b6a28e8b12647d0873cf623c4bcf03f3afe22c"
}
],
"package_integrity": [
{
"filename": "monitoring-agent-1.0.1.tgz",
"hashes": {
"sha1": "f0555042009d4f3708fd80859b7d39ab95f91e82",
"sha512_sri": "sha512-NJOemjl/hq2ehMts1chz2YsuDr4O37FhNYQprI6QFB+JuZs2+9FYWFHA6/7xFjqSlm5+a/bGAvh5D1uD7y3kKg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/monitoring-agent/MAL-2026-17515.json"