-= Per source details. Do not edit below this line.=-
The package name is a single-character transposition of axios. package.json declares preinstall, install, and postinstall hooks all pointing at postinstall.js, guaranteeing execution on npm install. postinstall.js reads ~/.ssh/id_*, ~/.aws/credentials, ~/.aws/config, ~/.config/gcloud/application_default_credentials.json, ~/.azure/accessTokens.json, ~/.npmrc, shell histories, browser profile data, crypto wallet files, the entire process.env, and recursively walks ~/projects, ~/dev, ~/code, ~/workspace, and the current working directory for .env files. Collected data is POSTed via plain HTTP to http://80.200.28.28:2222/collect (hardcoded as C2_HOST at line 11). Author comments in the source explicitly label installers as 'victims' (// Change this to your PUBLIC IP when deploying to victims) and construct a VICTIM_ID, leaving no benign interpretation. The exposed fetchData API in index.js is a stub that only console.logs — the package has no legitimate function.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-003365",
"import_time": "2026-05-26T05:50:30.038124505Z",
"modified_time": "2026-05-20T01:33:43Z",
"sha256": "2c958ad366d3cf211d3687734b5515662d21eb63135675984966149e7205f5ee",
"source": "amazon-inspector",
"versions": [
"1.0.9"
]
},
{
"id": "IN-MAL-2026-003366",
"import_time": "2026-05-26T05:50:30.129341041Z",
"modified_time": "2026-05-20T01:33:43Z",
"sha256": "348b9dab1b41fbf96d8b2eb2d57a630c5173a7a59b446495ae44f2c8c270fc54",
"source": "amazon-inspector",
"versions": [
"1.0.9"
]
},
{
"id": "IN-MAL-2026-003383",
"import_time": "2026-05-26T05:50:32.292390413Z",
"modified_time": "2026-05-20T01:48:45Z",
"sha256": "3bde7de4bfb2aa11618fdd40c2fa9148ea6528d5e0e198bf2a7148d013021d6b",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-003384",
"import_time": "2026-05-26T05:50:32.381114054Z",
"modified_time": "2026-05-20T01:56:23Z",
"sha256": "48eb1a16cb7cac016f30a49f81d472b9b4e02236b97c5daaea4446b74e6aa069",
"source": "amazon-inspector",
"versions": [
"1.0.5"
]
},
{
"id": "IN-MAL-2026-003373",
"import_time": "2026-05-26T05:50:30.947293738Z",
"modified_time": "2026-05-20T01:42:02Z",
"sha256": "6c7f0094b893662a5bccb61ccbb5acdc9cef0e7d29361133c47456ace1d46836",
"source": "amazon-inspector",
"versions": [
"1.0.6"
]
},
{
"id": "IN-MAL-2026-003370",
"import_time": "2026-05-26T05:50:30.567604347Z",
"modified_time": "2026-05-20T01:40:54Z",
"sha256": "96352f83bd4eb19f3b558b436dbcb497759f2f44c09ba6e9f0c283a2bdf4b61a",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-003382",
"import_time": "2026-05-26T05:50:32.196030532Z",
"modified_time": "2026-05-20T01:48:45Z",
"sha256": "a0138ed11110dbbde8b54451da2c6a188d1ce1b885f57b4502b0e3d15af797cc",
"source": "amazon-inspector",
"versions": [
"1.0.8"
]
},
{
"id": "IN-MAL-2026-003369",
"import_time": "2026-05-26T05:50:30.473042333Z",
"modified_time": "2026-05-20T01:40:53Z",
"sha256": "ebd0e0c4d55ecc3d8d7d292bfbf40484d853466a4b12cbd7a4da5171cac12e74",
"source": "amazon-inspector",
"versions": [
"1.0.7"
]
},
{
"id": "IN-MAL-2026-003379",
"import_time": "2026-05-26T05:50:31.871438811Z",
"modified_time": "2026-05-20T01:44:45Z",
"sha256": "ef6753fc762c223001f634d4abd6f0fd9e578ec3b042931a2b4ea0cdaab1ef26",
"source": "amazon-inspector",
"versions": [
"1.0.4"
]
},
{
"id": "RLMA-2026-04953",
"import_time": "2026-07-09T09:16:18.70394551Z",
"modified_time": "2026-07-07T12:40:36Z",
"sha256": "27bd573042acab3a2f8d6f9bdc710d06c48c53ae728f32db90621ffe6f81c4e8",
"source": "reversing-labs",
"versions": [
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.9"
]
},
{
"id": "RLUA-2026-06078",
"import_time": "2026-09-01T11:17:56.877764463Z",
"modified_time": "2026-08-24T16:40:44Z",
"sha256": "6350a5cf6957e04ea75045122049f8e3d499c34bd5be352194cef68b8a27db82",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"api.ipify.org",
"b94b6bcfa27554.lhr.life"
],
"evidence_files": [
{
"path": "distrube.js",
"sha256": "308b15c023088a7188dea4ef609010ac2493eb4c365b103053d7621a9ca5b935",
"tlsh": "6b3293e066f79160127395aa832ba5061177f0033902edb8ff9dd3451f8a52c87f26ed"
}
],
"package_integrity": [
{
"filename": "axois-utils-1.0.9.tgz",
"hashes": {
"sha1": "1e3108220b931a6a8005b6f19cd729856847fc64",
"sha512_sri": "sha512-EX4QmTBU8U1aSejnWVtJiF+EisFnm+0NH5YqaJLddrK91ttXJ01lTiYi+ihetV6wxeI9HFLnuCEQ8KThl+DiQg=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axois-utils/MAL-2026-4494.json"