MAL-2026-3770

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/prisma-callback/MAL-2026-3770.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-3770
Aliases
  • GHSA-rj6f-xp57-j95c
Published
2026-05-14T19:25:22Z
Modified
2026-07-31T01:38:51.363122628Z
Summary
Malicious code in prisma-callback (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1aab2820bfb9036995418ba2b36887f8970d7deaa69d8bc4aa24e36266bf18d1)

prisma-callback@1.0.3 is a name-confusion package against the genuine prisma ORM. Its package.json declares "preinstall": "node./scripts/only-allow-pnpm.js pnpm"; despite the misleading filename, that script dispatches on os.arch() and unconditionally executes one of two Go binaries shipped at the tarball root — prisma-amd64 (sha256 7255674131eee4a4b9adb12196a1b66e3faad9ee60740ab01b4d4e91bf8a30a8, 1,597,624 bytes) or prisma-arm64 (sha256 270769b70e1fe3718243e5f2f4655d9dd5d3b9f6e7217919d724859f7d6a66db, 2,162,872 bytes) — via child_process.execSync with inherited stdio, running under whatever privileges npm install holds. Neither binary exists in the genuine Prisma source tree; both are opaque compiled artifacts the installer cannot inspect or verify. To lower scrutiny, the tarball ships a verbatim copy of the real Prisma monorepo (README badges, issue templates, and every sub-package's package.json point at github.com/prisma/prisma), and the preinstall script carries a // This script is safe — it's only used for testing purposes. comment to discourage review. The structural signals — typosquat of a top-tier OSS package + undeclared opaque native binaries + preinstall-time execution without integrity verification + deliberate misdirection via filename, comment, and legitimate-looking cover source — are jointly unambiguous.

Source: ghsa-malware (acf13995d180b6da629b2f576c0a4ad6511839cdf01f579325fdf486d25ea257)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "1aab2820bfb9036995418ba2b36887f8970d7deaa69d8bc4aa24e36266bf18d1",
            "modified_time": "2026-05-14T19:25:23Z",
            "versions": [
                "1.0.3"
            ],
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-002719",
            "import_time": "2026-05-15T07:37:17.926126415Z"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-05-14T19:25:24Z",
            "versions": [
                "1.0.5"
            ],
            "sha256": "62be29d2f9abe77cef6476832d0b374e005837261dd463c9a8cb050264d09c12",
            "id": "IN-MAL-2026-002721",
            "import_time": "2026-05-15T07:37:18.013718115Z"
        },
        {
            "import_time": "2026-05-15T07:37:17.966551837Z",
            "modified_time": "2026-05-14T19:25:23Z",
            "versions": [
                "1.0.4"
            ],
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-002720",
            "sha256": "824aa4cb44af4f45df5c6cfe9c1164068a4fe79960461961025db0e2359b4f0c"
        },
        {
            "sha256": "f2f308e7edaeeb371dd02a2d7aa5d693ef8fba9db1d4121b0798986fcf492347",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ],
            "modified_time": "2026-05-14T19:25:22Z",
            "id": "IN-MAL-2026-002718",
            "import_time": "2026-05-15T07:37:17.862432325Z"
        },
        {
            "source": "ghsa-malware",
            "sha256": "acf13995d180b6da629b2f576c0a4ad6511839cdf01f579325fdf486d25ea257",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "modified_time": "2026-07-30T22:14:59Z",
            "id": "GHSA-rj6f-xp57-j95c",
            "import_time": "2026-07-31T01:10:09.711662478Z"
        }
    ]
}
References
Credits

Affected packages

npm / prisma-callback

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0
1.0.3
1.0.4
1.0.5

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/prisma-callback/MAL-2026-3770.json"
indicators
{
    "evidence_files": [
        {
            "path": "scripts/only-allow-pnpm.js",
            "sha256": "c62e5487e96665c1c83d9507b77752e04d7a86c181359ca8ab99e141a0a75ff1",
            "tlsh": "10d02be04647f2f0e4e414c0fe10f2524c138870b202a1e0a0ee80c217959dd051a5d4"
        },
        {
            "path": "package.json",
            "sha256": "7eca2d4131c9725569fa1a306dd0387ded1076acf49c475dc97b42c43450e111",
            "tlsh": "f0b1cb64ce910cf31a51967fa4294393212685074e96bd0cbbac526d8f0d3dfb0b2ead"
        }
    ],
    "package_integrity": [
        {
            "hashes": {
                "sha1": "b4fc627c249b6aae157a445a7809156196a712cd",
                "sha512_sri": "sha512-u9EThdWSgR/ZeaZHAqVbCOPetyiT5msJF3ImYZKTNlJxRYK7fdWc1taqPcyIaFahp0ZSOfs9Q1TLtt3x4SIQow=="
            },
            "filename": "prisma-callback-1.0.3.tgz"
        }
    ]
}