-= Per source details. Do not edit below this line.=-
The published tarball ships npmjs.npmrc containing a live npm_-prefixed authToken for registry.npmjs.org scoped to @arbocollab. package.json declares "files": ["*"] and .npmignore does not exclude npmjs.npmrc, so every installer receives the credential. The package.json publish:lib script references this same file via --userconfig=npmjs.npmrc, confirming it is the maintainer's real publish credential rather than a stub. Any installer or anyone who downloads the tarball can use this token to publish arbitrary malicious versions under the @arbocollab scope, pivoting into a supply-chain attack against all downstream consumers of any package in that scope. No install-time hooks are present; the harm is the credential redistribution itself. Remediation: revoke the token immediately, unpublish/deprecate affected versions, remove npmjs.npmrc from the published tarball, and add it to .npmignore/files allowlist.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004624",
"import_time": "2026-05-26T05:52:58.258142836Z",
"modified_time": "2026-05-25T10:38:13Z",
"sha256": "3f007c3da95aa64e4c2ed5b51b736900ddc444499f2f678d749603fab516a0c3",
"source": "amazon-inspector",
"versions": [
"0.26.3-alpha.13"
]
},
{
"id": "IN-MAL-2026-004589",
"import_time": "2026-05-26T05:52:53.909955945Z",
"modified_time": "2026-05-25T06:21:44Z",
"sha256": "4821627bbaf9dd52acb4f81cd41314885366cee188c4a4a1f280df73eb237afa",
"source": "amazon-inspector",
"versions": [
"0.26.3-alpha.9"
]
},
{
"id": "IN-MAL-2026-003256",
"import_time": "2026-05-26T05:50:18.271220734Z",
"modified_time": "2026-05-19T19:07:53Z",
"sha256": "7eabee413f8b1629aed91fce8717e416307c0cfe94c035180e99c1a2cbd17978",
"source": "amazon-inspector",
"versions": [
"0.26.3-alpha.7"
]
},
{
"id": "IN-MAL-2026-004592",
"import_time": "2026-05-26T05:52:54.312117589Z",
"modified_time": "2026-05-25T06:38:42Z",
"sha256": "91da50a4adf630e58c7d161164d7ffdd01d5f6bbe3f8265acff32aeabef9d44b",
"source": "amazon-inspector",
"versions": [
"0.26.3-alpha.10"
]
},
{
"id": "IN-MAL-2026-004901",
"import_time": "2026-05-26T13:32:46.305010097Z",
"modified_time": "2026-05-26T11:01:59Z",
"sha256": "2dc551980e00305aca3a1a7047ecaf4e65b69aa9ef4dcd6ca489a2d828ab1a88",
"source": "amazon-inspector",
"versions": [
"0.26.3-alpha.15"
]
},
{
"id": "IN-MAL-2026-004899",
"import_time": "2026-05-26T13:32:46.175698146Z",
"modified_time": "2026-05-26T10:45:57Z",
"sha256": "d59e5635dbfbe63e57949b98ea9df0b8a601dbeb017c1a535879d016bb648f20",
"source": "amazon-inspector",
"versions": [
"0.26.3-alpha.14"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "npmjs.npmrc",
"sha256": "3fd0ea889836389cf540294ee0deb2af8c070683c235ad46b1854c27ab75dd9a",
"tlsh": "d7c09b7f4d1e990367e0d5dd8c40b4154eaa44c34fef46d2f3650fdc49819c2302681b"
},
{
"path": "package.json",
"sha256": "57369a1191684be202de5a2d48c8e7b6861f64072c9ddc4daf6e47c9c96cbddd",
"tlsh": "8721722ac8c84e0321985a54bc284222d776125b68e07e853bdf12ac4f8e6af317e10d"
}
],
"package_integrity": [
{
"filename": "arbo-web-people-0.26.3-alpha.13.tgz",
"hashes": {
"sha1": "6574da6feb7b799a5800d0cfdd789b0a414b37c1",
"sha512_sri": "sha512-mf8oLFq2JfLc8J/bTVWNjh/1XwX4tOzbaMUGmJYlFhXwxtp4SwuKAoBDDk5ZmwNPfNw7yeHb3+9mwMVQUhTWUQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@arbocollab/arbo-web-people/MAL-2026-4362.json"