MAL-2026-4395

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@inetafrica/open-claudia/MAL-2026-4395.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4395
Withdrawn
2026-05-26T18:04:02Z
Published
2026-05-22T09:30:38Z
Modified
2026-08-06T15:34:46Z
Summary
Malicious code in @inetafrica/open-claudia (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1d2fde4b2f69d2aa99c4fcc7ed5b04bd029394caf40067eb2be6987bf30a1b03)

The package ships multiple modules (health.js, setup.js, bot.js, core/media.js, core/handlers.js) that combine child_process, fs, and https to build and POST payloads to hardcoded network destinations, including https://api.telegram.org. health.js at line 95 issues https.get against api.telegram.org and reads process.env, process.platform, and process.version alongside filesystem probes. setup.js at lines 79/92/95 makes https.get/https.request/POST calls to api.telegram.org while reading process.env at lines 317/362 and platform info at line 156, and also references huggingface.co at line 259. bot.js at line 18 pulls in child_process and at lines 166/184/185/217 performs POST/https.get operations while enumerating the filesystem (fs.existsSync, fs.readdirSync at lines 143-144) and reading process.env at lines 96/179. core/scheduler.js at line 128 spawns a shell ("sh"). core/handlers.js at line 614 POSTs after invoking whoami (lines 373, 473) and hostname (line 615). The recurring pattern across these files is: read installer-side identity/environment data (process.env, hostname, whoami, filesystem contents), then transmit it to a hardcoded Telegram Bot API endpoint that is not configured by the caller. Telegram Bot API is a documented exfiltration channel in supply-chain attacks because the destination host is neutral infrastructure and the bot token embedded in the code selects the attacker-controlled recipient chat.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004177",
            "import_time": "2026-05-26T05:52:05.215343928Z",
            "modified_time": "2026-05-22T09:30:38Z",
            "sha256": "09b3881ec598069649e57612f04359886ef22331899541885248ea6a0a41bce2",
            "source": "amazon-inspector",
            "versions": [
                "2.2.15"
            ]
        },
        {
            "id": "IN-MAL-2026-004474",
            "import_time": "2026-05-26T05:52:40.282374032Z",
            "modified_time": "2026-05-24T09:16:41Z",
            "sha256": "766e927208a79fafba984ef22edef82ea87cdb9c520c5e9cbaa9e63fd47be70e",
            "source": "amazon-inspector",
            "versions": [
                "2.2.16"
            ]
        },
        {
            "id": "IN-MAL-2026-016608",
            "import_time": "2026-08-06T15:19:32.608383561Z",
            "modified_time": "2026-08-06T14:21:00Z",
            "sha256": "17430fece467aa5f1acf023682c9836f917e32b3f8dc652aff9b8dcd37f745d3",
            "source": "amazon-inspector",
            "versions": [
                "3.1.16"
            ]
        },
        {
            "id": "IN-MAL-2026-016616",
            "import_time": "2026-08-06T15:19:33.232623367Z",
            "modified_time": "2026-08-06T14:22:13Z",
            "sha256": "1a939f70dcc88e7b0e80fcecc3eef83786c5717c133cffd1da1af8e6a7fb42eb",
            "source": "amazon-inspector",
            "versions": [
                "3.1.21"
            ]
        },
        {
            "id": "IN-MAL-2026-016603",
            "import_time": "2026-08-06T15:19:32.328619977Z",
            "modified_time": "2026-08-06T14:20:13Z",
            "sha256": "28327cc6a3a280a3d26c67d6901c80380938f713c20dd1fb2d5cfc7e131969aa",
            "source": "amazon-inspector",
            "versions": [
                "3.1.24"
            ]
        },
        {
            "id": "IN-MAL-2026-016620",
            "import_time": "2026-08-06T15:19:33.482878435Z",
            "modified_time": "2026-08-06T14:22:44Z",
            "sha256": "2b64b3b8eb3f6fb672ae7bf27e958fdfe0d3c0669be7dd3bb7a626f159b7765c",
            "source": "amazon-inspector",
            "versions": [
                "3.1.7"
            ]
        },
        {
            "id": "IN-MAL-2026-016615",
            "import_time": "2026-08-06T15:19:33.163671508Z",
            "modified_time": "2026-08-06T14:21:58Z",
            "sha256": "523fd8f6cad83c8df6dbb7d9fda547714a289d8f8710c281d6947d94aebe0d09",
            "source": "amazon-inspector",
            "versions": [
                "3.0.35"
            ]
        },
        {
            "id": "IN-MAL-2026-016614",
            "import_time": "2026-08-06T15:19:33.118566613Z",
            "modified_time": "2026-08-06T14:21:51Z",
            "sha256": "a848cf77afff956e5fd6300d61393940fba9181c509b2ee1b2b72e8028f29842",
            "source": "amazon-inspector",
            "versions": [
                "3.1.13"
            ]
        },
        {
            "id": "IN-MAL-2026-016606",
            "import_time": "2026-08-06T15:19:32.519376227Z",
            "modified_time": "2026-08-06T14:20:41Z",
            "sha256": "de9795e8644235fbeb4ad50e17823eb7b68b6ac1a6ea299b8c9d51b771563632",
            "source": "amazon-inspector",
            "versions": [
                "3.1.17"
            ]
        },
        {
            "id": "IN-MAL-2026-016605",
            "import_time": "2026-08-06T15:19:32.453851088Z",
            "modified_time": "2026-08-06T14:20:30Z",
            "sha256": "ed83f7ae0e77ccef701306cfb53a0d0d12093cefa8b94f7d6d4c93577c4ed585",
            "source": "amazon-inspector",
            "versions": [
                "3.1.14"
            ]
        },
        {
            "id": "IN-MAL-2026-016613",
            "import_time": "2026-08-06T15:19:33.002850603Z",
            "modified_time": "2026-08-06T14:21:41Z",
            "sha256": "63b0cc86cf0332c9976c6a6392e1760cfb56c91eae6c41e7c9f1716526f871a3",
            "source": "amazon-inspector",
            "versions": [
                "3.1.27"
            ]
        },
        {
            "id": "IN-MAL-2026-016602",
            "import_time": "2026-08-06T15:19:32.287920766Z",
            "modified_time": "2026-08-06T14:20:05Z",
            "sha256": "d218226a38e557f4d0af2b28c153495239d6bddb8fd9b39c8003e8925e948573",
            "source": "amazon-inspector",
            "versions": [
                "3.1.23"
            ]
        },
        {
            "id": "IN-MAL-2026-016612",
            "import_time": "2026-08-06T15:19:32.873381952Z",
            "modified_time": "2026-08-06T14:21:33Z",
            "sha256": "e30c3f7eaf5dac32ffb90a2f361393536ca0949c0efd01100fde788f6416fc2d",
            "source": "amazon-inspector",
            "versions": [
                "3.1.4"
            ]
        },
        {
            "id": "IN-MAL-2026-016618",
            "import_time": "2026-08-06T15:19:33.375803272Z",
            "modified_time": "2026-08-06T14:22:28Z",
            "sha256": "13aad10d2600f9b0b64d61cbb52a61dcff4eccec01c0ade268cbb6ecd30d3078",
            "source": "amazon-inspector",
            "versions": [
                "3.1.26"
            ]
        },
        {
            "id": "IN-MAL-2026-016617",
            "import_time": "2026-08-06T15:19:33.296793886Z",
            "modified_time": "2026-08-06T14:22:20Z",
            "sha256": "1d2fde4b2f69d2aa99c4fcc7ed5b04bd029394caf40067eb2be6987bf30a1b03",
            "source": "amazon-inspector",
            "versions": [
                "3.1.3"
            ]
        },
        {
            "id": "IN-MAL-2026-016607",
            "import_time": "2026-08-06T15:19:32.575810114Z",
            "modified_time": "2026-08-06T14:20:51Z",
            "sha256": "5f001db733ff6b8707fb5ecb172ca1f43f155eb0c323d5af6738488e40477106",
            "source": "amazon-inspector",
            "versions": [
                "3.0.43"
            ]
        },
        {
            "id": "IN-MAL-2026-016610",
            "import_time": "2026-08-06T15:19:32.721334127Z",
            "modified_time": "2026-08-06T14:21:17Z",
            "sha256": "74d3c31956687b6ce17e1fba19b9fce658256b1fe77c6e2ef9d3fc9fa1de7c82",
            "source": "amazon-inspector",
            "versions": [
                "3.1.25"
            ]
        },
        {
            "id": "IN-MAL-2026-016611",
            "import_time": "2026-08-06T15:19:32.797523853Z",
            "modified_time": "2026-08-06T14:21:25Z",
            "sha256": "aa2a2118fb019661aaa00dc0da79d99ae27e1796a9fb3c4c0ed7b128fad99540",
            "source": "amazon-inspector",
            "versions": [
                "3.1.22"
            ]
        },
        {
            "id": "IN-MAL-2026-016619",
            "import_time": "2026-08-06T15:19:33.42181971Z",
            "modified_time": "2026-08-06T14:22:36Z",
            "sha256": "c0b999b117766264f9802d91fa0af7c1112e0641821254bd72062a041725316a",
            "source": "amazon-inspector",
            "versions": [
                "3.2.0"
            ]
        },
        {
            "id": "IN-MAL-2026-016609",
            "import_time": "2026-08-06T15:19:32.656879326Z",
            "modified_time": "2026-08-06T14:21:07Z",
            "sha256": "3c7d8872721b32229715234c263d28ace5a2e88ea7212aafe0a587df7e68620f",
            "source": "amazon-inspector",
            "versions": [
                "3.1.28"
            ]
        },
        {
            "id": "IN-MAL-2026-016604",
            "import_time": "2026-08-06T15:19:32.37506554Z",
            "modified_time": "2026-08-06T14:20:20Z",
            "sha256": "889d907305a04d6ef03fdf838789c927a101f3956dee9a10523a5979666fe66e",
            "source": "amazon-inspector",
            "versions": [
                "3.0.34"
            ]
        },
        {
            "id": "IN-MAL-2026-016601",
            "import_time": "2026-08-06T15:19:32.254085768Z",
            "modified_time": "2026-08-06T14:19:57Z",
            "sha256": "ed4180eea0f57cfa56162c91bb6ff60d4bf03b55136b22f4453e881ec13a558d",
            "source": "amazon-inspector",
            "versions": [
                "3.1.12"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @inetafrica/open-claudia

Package

Name
@inetafrica/open-claudia
View open source insights on deps.dev
Purl
pkg:npm/%40inetafrica/open-claudia

Affected ranges

Affected versions

2.*
2.2.15
2.2.16
3.*
3.0.34
3.0.35
3.0.43
3.1.3
3.1.4
3.1.7
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.21
3.1.22
3.1.23
3.1.24
3.1.25
3.1.26
3.1.27
3.1.28
3.2.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "bin/cli.js",
            "sha256": "d889293dcda5793c428ba196ef5a058ab5a2436f953b537e5e86e5e4ffafe72c",
            "tlsh": "0232a745dafe297247b7926a170b20237b55d6133204cc64b6ece3a6bf85094d2f39ec"
        },
        {
            "path": "bot-agent.js",
            "sha256": "6b3c9b7184f6b394b1e5a49972d0caaa86165d13d8c5c803a79f78180abf874e",
            "tlsh": "d493f93560fb653176a2e06da31b602b7b3ab1173204e5a4b59cb6442fdd168c1f3bbc"
        },
        {
            "path": "bot.js",
            "sha256": "f54f63c6037b7a6ca3dd3eb4bc2e333c3d65982ffe97676a41f642316627c9e6",
            "tlsh": "13f1b7761afa01327473d28e8a0b501679a7f5073308c9d4765df26a1fce46487b6bf8"
        },
        {
            "path": "core/handlers.js",
            "sha256": "a99a80da9ec7d66d135b3a97bcab1685ab798bba120436f48f4494a916882c1d",
            "tlsh": "ec53f8a460bb903169f7f15e5b1b1117372aa3173218d494b95ce3082fee159c2befe8"
        },
        {
            "path": "core/loopback.js",
            "sha256": "b3584055d8e9b758020ae95531db7fbb1281bae9a61ed1d8897fd5e61f584928",
            "tlsh": "91a2778639a2b022db772128969bec16b36ef947784dc894b78c4650ffd30649376fc4"
        },
        {
            "path": "health.js",
            "sha256": "79a2d267b44f8a417e759c1dd423abf2064922bb51687046fdfaeb16a92525ef",
            "tlsh": "3d72668e0de673359ba1a2696b0b60227365b143220cfd54f6dd92703f5d03452fbbea"
        },
        {
            "path": "setup.js",
            "sha256": "8aee04e520de5b1b33682fc842748b693feec976c4787d919ade56cdfdb98e9a",
            "tlsh": "55d2a3754afa5134757ae06d974b501632a4b5173209ec6433dcb3a91fee82880bbefc"
        },
        {
            "path": "web.js",
            "sha256": "8cebe8c91daac4c4a7e218e85cb9ac4101be297f3771a9327a65d0bf6c7e0ed5",
            "tlsh": "bbe2c6b220e7092733a6d16c4657821a7761f517f00a8e60faac71982fdf865c1b79f8"
        }
    ],
    "package_integrity": [
        {
            "filename": "open-claudia-2.2.15.tgz",
            "hashes": {
                "sha1": "d71e44dde5fcf517ab243d1ec0154be4a5d84b0e",
                "sha512_sri": "sha512-rau9m7jfP9l/YZCjoSYmUFjiBtc103qeI7sfR0QWPHMNhEeQA3+1mLWDd0aCpQrFnHCLqnRILKTGGo0l9JnDAA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@inetafrica/open-claudia/MAL-2026-4395.json"