-= Per source details. Do not edit below this line.=-
The bundled CLI (dist/index.js) contains a hardcoded outbound POST to https://sema.otimitare.online combined with reads of process.env and process.platform in the same module. The destination domain does not match any documented publisher infrastructure for a CLI tool and the call site issues an HTTP POST carrying environment- and platform-derived data. This pattern — hardcoded non-publisher C2 + env/platform reads + POST in a tool's main bundled entry — is the exfiltration shape and not consistent with normal telemetry from a reputable vendor (no opt-out, undocumented destination, suspicious lookalike-style hostname under a generic.online TLD).
{
"malicious-packages-origins": [
{
"import_time": "2026-05-26T05:50:44.704163199Z",
"source": "amazon-inspector",
"sha256": "28a3662b8e26593b7bfec35d4d4f02595144885ee738891c4c9e6a89f9e50fbb",
"versions": [
"1.5.28"
],
"id": "IN-MAL-2026-003501",
"modified_time": "2026-05-20T08:31:36Z"
}
]
}{
"evidence_files": [
{
"tlsh": "fb54d75a59f705121e7722a86a8b4013b9385e432d0ced4abb5d83d01fcd96d92f3bec",
"sha256": "c65ca3fbab007b8e6861743a487d64ba6e322544a5e7474dc3089f8a2f832fac",
"path": "dist/index.js"
}
],
"package_integrity": [
{
"filename": "cli-1.5.28.tgz",
"hashes": {
"sha1": "7ddbe9b44e014ac9cdaf01b67b64a5059eae0e6a",
"sha512_sri": "sha512-Afdnku795+xMei6kdxLNH1aVX5XSKzngLHjzKVbjJc3k6u/GZSzNGdZOJJSd6gS2KdCjzhgaTda7mPm2wAz9IQ=="
}
}
]
}
[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@semacode/cli/MAL-2026-4434.json"