-= Per source details. Do not edit below this line.=-
index.js, the package's main entry, runs at require() time with no user interaction. On load it spawns OS-native calculator processes via child_process.exec ('calc.exe' on Windows, 'open -a Calculator' on macOS, 'gnome-calculator' on Linux) to demonstrate arbitrary code execution; writes a marker file to the user's Desktop (INSOMNIA_RCE_PROOF.txt); and serializes the full process.env object with JSON.stringify and emits it to the console, disclosing any tokens, API keys, and other secrets present in the environment of the host process (typically Insomnia on a developer machine). The source comments self-identify the module as a proof-of-concept remote code execution payload targeting Insomnia's plugin loader. The arbitrary-exec, filesystem write outside the package directory, and bulk environment enumeration all fire unconditionally at load.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021012",
"import_time": "2026-10-05T03:57:38.606751862Z",
"modified_time": "2026-10-05T03:35:16Z",
"sha256": "f3572e41f2e2e83a3156c1b24bf8684c0149a508e45626e80c592657cfb475ba",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "ef40b0021ce91965d33e7fadba98d0466c71ca52773f3ccaf2d269af39d1d62e",
"tlsh": "af51846467f8537611b11161c28d64a33baec2274795bb25f08d87692b8cc5883b36f9"
}
],
"package_integrity": [
{
"filename": "insomnia-plugin-api-lint-helper-1.0.0.tgz",
"hashes": {
"sha1": "bffb0f33847b405a039e6f11d855232653474ed8",
"sha512_sri": "sha512-yxHcL/vX7q4sE5vYcsz1PoBqHaftAosTlVayijjXDscnspgZmqssPR+z1iQ7zyMq2VGEZd7nrKcFVpiyZxHh+A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/insomnia-plugin-api-lint-helper/MAL-2026-17561.json"