-= Per source details. Do not edit below this line.=-
The main entrypoint index.js runs an IIFE at require time that monkey-patches the global console.warn and console.error methods. After the override, every subsequent console.warn/console.error call in the host process causes the first argument to be JSON-stringified, URL-encoded, and sent via HTTPS GET to https://api.telegram.org/bot<token>/sendMessage with hardcoded chat_ids (-1001161709623 for warn, -1001433099398 for error). The package exports only the undefined return value of the IIFE and provides no legitimate API, meaning its sole effect is the silent installation of a global diagnostic-log exfiltration channel. Any installer whose code runs console.warn/console.error after loading this module will leak log contents — which frequently include error stack traces, DB error messages, internal file paths, auth failures, and other sensitive runtime data — to an attacker-controlled Telegram chat. Additional unreachable files (t.js, o.js, jq.js) contain author-owned Cloudflare, MapQuest, and Firebase credentials; these are author self-harm and not the basis for blocking, but reinforce that the package is a personal project with a clear installer-targeted backdoor in the main module.
{
"malicious-packages-origins": [
{
"sha256": "0daa9fcdb5d5f8808d593664e1b459e30660c8749d7c37dbe39fad309d53c2ec",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.1.1"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002489",
"import_time": "2026-05-13T20:10:57.9763455Z"
},
{
"sha256": "46f300e5c1c263dd0307e51ce4c6146c3bb6154eb4b45093d7dfc21378b90ac0",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.4.8"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002503",
"import_time": "2026-05-13T20:10:59.355144775Z"
},
{
"sha256": "a5c54735e94f20ebb4b49b4177b53ba59461d01d657179d7ce74bc3372f74bf5",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.2.6"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002494",
"import_time": "2026-05-13T20:10:58.529581793Z"
},
{
"sha256": "b51245ca46fd91fd3c5ead2e0ac6c307c79426ec89192cc4b8de4a370901baf8",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.3.6"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002500",
"import_time": "2026-05-13T20:10:59.065627908Z"
},
{
"sha256": "c7c50f85652ce401d24ae482911088ba99a9c0bbc20c557b8cce7d07559b59b1",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.0.2"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002487",
"import_time": "2026-05-13T20:10:57.844622729Z"
},
{
"sha256": "d98117e6352bdd43b27d69a1e157fbfd0792fc629f42f910b7aed480f6c50ac3",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.2.4"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002495",
"import_time": "2026-05-13T20:10:58.601814292Z"
},
{
"sha256": "dfd483376dbe937b7e7944ef32e50ac3fae4144f8f2825b3eb2abfbd6009f10f",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.4.9"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002504",
"import_time": "2026-05-13T20:10:59.404523488Z"
},
{
"sha256": "181f84c5f19279c4de19e1dcc4ab8968c1a96dc20ad4801e555fb55b45144c48",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.1.4"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002490",
"import_time": "2026-05-13T20:10:58.153834761Z"
},
{
"sha256": "471e567a6621adb423bb511da078fc447bf20839bbc219d9e91d21216427e20f",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.4.6"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002501",
"import_time": "2026-05-13T20:10:59.166706918Z"
},
{
"sha256": "514aa6166f2c533d4eb01618bf699f05b80f71182021bd11125e6bfa47b3451a",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.3.3"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002498",
"import_time": "2026-05-13T20:10:58.919194208Z"
},
{
"sha256": "6da9a1199176e2f5ccc8b7a2ad8b199fdf2ee3256282fb65d693fc0c36e621a8",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.0.7"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002488",
"import_time": "2026-05-13T20:10:57.894271951Z"
},
{
"sha256": "ad5fecc5879a38dfd2ab65870607b5b901efcf12588e4ac884eef9302291fb07",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.3.5"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002499",
"import_time": "2026-05-13T20:10:58.992137941Z"
},
{
"sha256": "bb8c30d7cc35d6f8f3a8d4827195bad9da5cb74720dc385bcfec156ccd7e4464",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.2.3"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002492",
"import_time": "2026-05-13T20:10:58.282331085Z"
},
{
"sha256": "fbfaaf434d15398e9b0c645145489909ea3ff45fa8e155dfee7d830e3a4c7758",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.2.5"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002493",
"import_time": "2026-05-13T20:10:58.40043631Z"
},
{
"sha256": "d00b5a2b45065c4989659e04a1216635187c72b794e741a3600b16ee71f14939",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.4.7"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002502",
"import_time": "2026-05-13T20:10:59.29018237Z"
},
{
"sha256": "73d938c4e6ec0dc716f1e2f02365307ffeb88d1253ef924f3da6dae795ae9839",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.2.7"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002496",
"import_time": "2026-05-13T20:10:58.73002355Z"
},
{
"sha256": "cb830829cae1605ff7626653a2470db03cd5a5aab98b3f0a7f5912eaf244561b",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.3.2"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002497",
"import_time": "2026-05-13T20:10:58.836818538Z"
},
{
"sha256": "f24a3b6ad6eacf11a818ca5e6d4f366d8bee9a4c348f474a2dfafcb2c7f8b80c",
"modified_time": "2026-05-12T19:03:07Z",
"versions": [
"1.1.5"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-002491",
"import_time": "2026-05-13T20:10:58.222393067Z"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/88q/MAL-2026-3676.json"
{
"domains": [
"api.telegram.org"
],
"evidence_files": [
{
"path": "index.js",
"sha256": "d1b881c129a1d8cc02851630fba441b73648681a2eced6710711c6f3663df3b3",
"tlsh": "3c11dc852efe90714c8a7015955b9107a5e5ea3b120cec20b64c82f02f31c92cbb2b89"
},
{
"path": "t.js",
"sha256": "0296ff2815758a68d3763c6e4af0a1c74ad58b965d97dea77abf98770b7a4669",
"tlsh": "16421f60a895b4732f12d26034ec6a1b9366525f2ca4fc21b9ce444f2f5cfeb2642ed4"
}
],
"package_integrity": [
{
"hashes": {
"sha1": "a3016309be328fc5459d91fc566c517cb1443b4d",
"sha512_sri": "sha512-1oWBMIsXMqbyVKJ2pdl6tXJwbIn53jvHqHwWMbTVfx7DGH6T5OCmKD095U3b1s74dlpdAvAAoVpGlpWJT3nMjw=="
},
"filename": "88q-1.1.1.tgz"
}
],
"urls": [
"https://api.telegram.org/bot848707422:AAGliik4xQpOpKOIP4qVss7BASJ3Ssw4uyA/sendMessage?chat_id=${x}&text=${encodeURIComponent(z"
]
}