MAL-2026-3309

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/google-cloud-secret-manager-config-poc/MAL-2026-3309.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3309
Published
2026-05-03T16:10:57Z
Modified
2026-05-12T07:57:09.873107Z
Summary
Malicious code in google-cloud-secret-manager-config-poc (npm)
Details

Malicious npm package published by the microsop threat actor as part of a dependency-confusion campaign that impersonates internal tooling at Microsoft, Google Cloud, and PayPal using inflated semver values (e.g. 99.9.x, 100.1.x) to win npm resolution against private internal packages. All packages in the campaign falsely advertise themselves as "Security Research PoC" and execute on preinstall via node index.js, exfiltrating to disposable webhook.site endpoints.

This package targets Google-Cloud-flavored internal naming and performs SSH key validation/fingerprinting on the build host. On install it checks for /root/.ssh/id_rsa, runs ssh-keygen -l -f to extract the key fingerprint and ssh-keygen -y -f to derive the public key, then POSTs {hostname, fingerprint, public_key, key_exists} to https://webhook.site/813b99f6-c86c-4a1f-9318-518a3c153992 tagged status: KEY_VALIDATION_RESULT. The captured fingerprint and public key let the operator correlate the install host against authorized-keys lists for downstream lateral movement.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (a4735e524b9623da4da209d597cdc515ed3f0cd2534591e1d98539d5b5f11f4c)

The package google-cloud-secret-manager-config-poc was found to contain malicious code.

Source: ossf-package-analysis (daa2f2438668b4ed2d4a869c9cd52cc3e989b235e08652eb8a041db22c222ae2)

The OpenSSF Package Analysis project identified 'google-cloud-secret-manager-config-poc' @ 99.9.14 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-05-04T03:13:24.730000059Z",
            "sha256": "daa2f2438668b4ed2d4a869c9cd52cc3e989b235e08652eb8a041db22c222ae2",
            "source": "ossf-package-analysis",
            "modified_time": "2026-05-03T16:10:57Z",
            "versions": [
                "99.9.14"
            ]
        },
        {
            "import_time": "2026-05-12T07:28:50.621462714Z",
            "sha256": "a4735e524b9623da4da209d597cdc515ed3f0cd2534591e1d98539d5b5f11f4c",
            "source": "amazon-inspector",
            "modified_time": "2026-05-12T06:53:21Z",
            "versions": [
                "99.9.14"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / google-cloud-secret-manager-config-poc

Package

Name
google-cloud-secret-manager-config-poc
View open source insights on deps.dev
Purl
pkg:npm/google-cloud-secret-manager-config-poc

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

99.*
99.9.14

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/google-cloud-secret-manager-config-poc/MAL-2026-3309.json"