-= Per source details. Do not edit below this line.=-
On npm install, the package's declared postinstall script executes index.js, which collects a host fingerprint (hostname, username, home directory, cwd, platform/arch/OS release, CPU model, memory, network interfaces including MAC/OUI, process info) and enumerates process.env for variable names matching TOKEN|SECRET|KEY|PASS|AWS_|GCP_|AZURE_|SSH|GIT|NPM|DOCKER. The collected data is transmitted via HTTPS GET to the hardcoded third-party endpoint telegrambot-aebk.onrender.com/ping. The behavior fires automatically on install without opt-in and discloses the installer's host identity and credential-variable inventory to an author-controlled destination.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021112",
"import_time": "2026-10-08T03:50:28.66592176Z",
"modified_time": "2026-10-08T03:37:45Z",
"sha256": "e6350184f3eabc17d37726cdd71ea97666cef28b2e1c125cffeb56e7c474b8dd",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "index.js",
"sha256": "1ad2ad5b251c088ccc219c5de1e11c0f5166e7a76e250ca13a50f15d326de018",
"tlsh": "2ed172b12da0543435b5d33d6b064123ea15bb133601e1a6bcbc72962fee864c169efe"
}
],
"package_integrity": [
{
"filename": "demo-canary-1.0.0.tgz",
"hashes": {
"sha1": "80c3675dbe6e2d7f45f86b6772d7dba1ae77bf35",
"sha512_sri": "sha512-d2nQDcRSLNTz2NRlhzARTOKNPtNa7kQZ+EsnM15fye6k7wBbmOHD/RQtVBp/VJvLBbH1Aw14BwF43SAMld90oA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@ziedzzz/demo-canary/MAL-2026-17652.json"