-= Per source details. Do not edit below this line.=-
rimraf-utils@1.0.5 impersonates the widely-installed rimraf package (index.js is a dummy stub that internally identifies itself as 'lodash-js — Just a dummy module. The real payload is in postinstall.js'). On npm install, scripts.postinstall runs postinstall.js, which harvests installer-side secrets and ships them to a hardcoded bare-IP C2 over plaintext HTTP at http://149.28.127.35:8888 (overridable via process.env.C2_URL).
Specific behavior in postinstall.js:
~/.npmrc (npm auth tokens), ~/.env (API keys, DB URLs, cloud credentials, payment keys, EVM private keys, webhooks), and ~/.git-credentials.os.hostname() and os.userInfo() for host identification..log files, regex-extracting vault/seed/mnemonic/privateKey/encrypted/password fields.~/Documents, ~/Desktop, ~/Downloads, ~/OneDrive, ~/Dropbox, ~/Google Drive, and backup/keys/wallet/crypto subtrees searching for seed-phrase and private-key patterns.http.request(...).This package matches multiple unambiguous attack fingerprints simultaneously: hardcoded bare-IP plaintext-HTTP C2 invoked from a lifecycle hook; browser crypto-wallet extension-ID enumeration; seed-phrase/mnemonic home-directory scanner; and installer-secret regex extraction from ~/.npmrc/~/.env/~/.git-credentials. The name is a typosquat of rimraf used as the delivery vector for the payload.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-002678",
"import_time": "2026-05-15T07:37:16.014381157Z",
"modified_time": "2026-05-14T19:25:01Z",
"sha256": "0514899c58dd41152ee9aeb101db1eec4a229ea907aa96f6bf9606b7a75cfe83",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "IN-MAL-2026-002679",
"import_time": "2026-05-15T07:37:16.060231882Z",
"modified_time": "2026-05-14T19:25:02Z",
"sha256": "8947f86d49a41e3f5b03eed92ee6a87e0e6438941606c25cac17c94da8ca9c08",
"source": "amazon-inspector",
"versions": [
"2.0.0"
]
},
{
"id": "IN-MAL-2026-002698",
"import_time": "2026-05-15T07:37:17.158478544Z",
"modified_time": "2026-05-14T19:25:11Z",
"sha256": "a59d88d733415216903578b3c3806d76405a23a7cca56ee355eb6725e4e930d4",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "6ac41974ce61de899439008088ad972e7ab2ac161b3abf61fcd6796f28a941d9",
"tlsh": "0452e994aaa9021c596382bbd75775b40499e90b35c1e8b4f78f03489f0974d2ef33bb"
},
{
"path": "package.json",
"sha256": "98ae1b8d6c3e001a0642d4b45934823f2888c1a2ed6cc4040bc27d136ee114b4",
"tlsh": "c4d02b208a129d3314c417671a6b420566f14d4b0148bc1c33db015c87aa3b68cff61e"
}
],
"package_integrity": [
{
"filename": "rimraf-utils-1.0.4.tgz",
"hashes": {
"sha1": "51b7f65b122b5c029b1e404869eb0e2e956de9c1",
"sha512_sri": "sha512-SzdPb1OuAUeUelQ9hHfVSFOEBdt/ekeLLr0grRcWDDP0aKdt1piTKT5t55fc1GDLYf7fbmOGmFQPNvjJ8TTS9A=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/rimraf-utils/MAL-2026-3772.json"