MAL-2026-4444

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@shwfed/nuxt/MAL-2026-4444.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4444
Published
2026-05-22T03:05:41Z
Modified
2026-06-12T20:01:52Z
Summary
Malicious code in @shwfed/nuxt (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (87ac343d6f89a601749bb115fa6902e7d39c71a0a6469690ecef56e9ea8a135e)

@shwfed/nuxt is published as a Nuxt UI module but contains undocumented build-hook code that, when a consumer integrates the module and runs a build under CI, POSTs the consumer's CI/build metadata and recent git history to a hardcoded third-party DingTalk webhook owned by the package author. In dist/module.mjs, the build:error and build:done Nuxt hooks invoke execSync("curl -s -X POST '${url}'... -d @-", { input: payload }) against https://oapi.dingtalk.com/robot/send with an embedded access_token (a01e0fdf...) and an embedded HMAC signing secret (SEC9d852...). The payload includes JOB_NAME, BUILD_NUMBER, branch name, RUN_DISPLAY_URL, build error message, the last 5 git log entries (commit subjects and author names) from the consumer's repository, and the last commit author. The destination is fixed in the source — not configurable, not documented, and unrelated to the module's advertised UI-component purpose. Any consumer that adds this module to their Nuxt config and runs CI builds leaks build status and recent git commit metadata (including third-party committer names) to the author's DingTalk channel without consent.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004583",
            "import_time": "2026-05-26T05:52:53.122336759Z",
            "modified_time": "2026-05-25T05:18:56Z",
            "sha256": "04c497e228a9ddf1560202c00b4a4a316bf4e44a76f032f35ac83da01ff5f866",
            "source": "amazon-inspector",
            "versions": [
                "0.13.0"
            ]
        },
        {
            "id": "IN-MAL-2026-004127",
            "import_time": "2026-05-26T05:51:59.368592186Z",
            "modified_time": "2026-05-22T03:05:41Z",
            "sha256": "87ac343d6f89a601749bb115fa6902e7d39c71a0a6469690ecef56e9ea8a135e",
            "source": "amazon-inspector",
            "versions": [
                "0.12.0"
            ]
        },
        {
            "id": "IN-MAL-2026-004128",
            "import_time": "2026-05-26T05:51:59.474234203Z",
            "modified_time": "2026-05-22T03:05:56Z",
            "sha256": "cc9864d615e6760cc4ce5f9037b93cb29a5f1c044cafa7736f7d3a953a42f6a4",
            "source": "amazon-inspector",
            "versions": [
                "0.12.0"
            ]
        },
        {
            "id": "IN-MAL-2026-004582",
            "import_time": "2026-05-26T05:52:53.019303786Z",
            "modified_time": "2026-05-25T05:18:52Z",
            "sha256": "0bf4290eabdf1af188406fbba698fba9e3d85b7a976bd5cc6fb77b862c0c1b2e",
            "source": "amazon-inspector",
            "versions": [
                "0.13.0"
            ]
        },
        {
            "id": "IN-MAL-2026-006155",
            "import_time": "2026-06-12T19:44:14.247531069Z",
            "modified_time": "2026-06-12T19:10:05Z",
            "sha256": "3336b06325a199568cd0fffee2cec27695d7e49be7d5cb333bcb3569ff846aec",
            "source": "amazon-inspector",
            "versions": [
                "0.13.1"
            ]
        },
        {
            "id": "IN-MAL-2026-006154",
            "import_time": "2026-06-12T19:44:14.153049153Z",
            "modified_time": "2026-06-12T19:10:05Z",
            "sha256": "63b019ca84778d17faf6bd57d455e1af9c7a07535d8cba7f69456d14e81419b2",
            "source": "amazon-inspector",
            "versions": [
                "0.13.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @shwfed/nuxt

Package

Name
@shwfed/nuxt
View open source insights on deps.dev
Purl
pkg:npm/%40shwfed%2Fnuxt

Affected ranges

Affected versions

0.*
0.12.0
0.13.0
0.13.1

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "domains": [
        "34.3.16.104.in-addr.arpa"
    ],
    "evidence_files": [
        {
            "path": "dist/module.mjs",
            "sha256": "2d91b00b8b9a6d98315e3559a46c4ee852785dcb69d0af5ef0f97219878948ab",
            "tlsh": "2ff1b71995a3352505f35911ab37280317be66436602fc14bf9e97d13f0f3a662f638d"
        }
    ],
    "package_integrity": [
        {
            "filename": "nuxt-0.12.0.tgz",
            "hashes": {
                "sha1": "2f6f7fb399d474dfd939876957be932a3de2c5db",
                "sha512_sri": "sha512-I3QnOJgcJDni1yqr6e6HLxUtQwe9UPgoB/npYBSe7+x+3y9hI9yPbRjaTRwg536ymyXOU93blW7T9OJVmLUrlQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@shwfed/nuxt/MAL-2026-4444.json"