MAL-2026-17561

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/insomnia-plugin-api-lint-helper/MAL-2026-17561.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17561
Published
2026-10-05T03:35:16Z
Modified
2026-10-05T04:15:05Z
Summary
Malicious code in insomnia-plugin-api-lint-helper (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f3572e41f2e2e83a3156c1b24bf8684c0149a508e45626e80c592657cfb475ba)

index.js, the package's main entry, runs at require() time with no user interaction. On load it spawns OS-native calculator processes via child_process.exec ('calc.exe' on Windows, 'open -a Calculator' on macOS, 'gnome-calculator' on Linux) to demonstrate arbitrary code execution; writes a marker file to the user's Desktop (INSOMNIA_RCE_PROOF.txt); and serializes the full process.env object with JSON.stringify and emits it to the console, disclosing any tokens, API keys, and other secrets present in the environment of the host process (typically Insomnia on a developer machine). The source comments self-identify the module as a proof-of-concept remote code execution payload targeting Insomnia's plugin loader. The arbitrary-exec, filesystem write outside the package directory, and bulk environment enumeration all fire unconditionally at load.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021012",
            "import_time":  "2026-10-05T03:57:38.606751862Z",
            "modified_time":  "2026-10-05T03:35:16Z",
            "sha256":  "f3572e41f2e2e83a3156c1b24bf8684c0149a508e45626e80c592657cfb475ba",
            "source":  "amazon-inspector",
            "versions":  [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / insomnia-plugin-api-lint-helper

Package

Name
insomnia-plugin-api-lint-helper
View open source insights on deps.dev
Purl
pkg:npm/insomnia-plugin-api-lint-helper

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "ef40b0021ce91965d33e7fadba98d0466c71ca52773f3ccaf2d269af39d1d62e",
            "tlsh":  "af51846467f8537611b11161c28d64a33baec2274795bb25f08d87692b8cc5883b36f9"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "insomnia-plugin-api-lint-helper-1.0.0.tgz",
            "hashes":  {
                "sha1":  "bffb0f33847b405a039e6f11d855232653474ed8",
                "sha512_sri":  "sha512-yxHcL/vX7q4sE5vYcsz1PoBqHaftAosTlVayijjXDscnspgZmqssPR+z1iQ7zyMq2VGEZd7nrKcFVpiyZxHh+A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/insomnia-plugin-api-lint-helper/MAL-2026-17561.json"