MAL-2026-4494

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axois-utils/MAL-2026-4494.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4494
Aliases
  • GHSA-pvvv-cmc6-c323
Published
2026-05-20T01:33:43Z
Modified
2026-09-01T11:31:05Z
Summary
Malicious code in axois-utils (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (48eb1a16cb7cac016f30a49f81d472b9b4e02236b97c5daaea4446b74e6aa069)

The package name is a single-character transposition of axios. package.json declares preinstall, install, and postinstall hooks all pointing at postinstall.js, guaranteeing execution on npm install. postinstall.js reads ~/.ssh/id_*, ~/.aws/credentials, ~/.aws/config, ~/.config/gcloud/application_default_credentials.json, ~/.azure/accessTokens.json, ~/.npmrc, shell histories, browser profile data, crypto wallet files, the entire process.env, and recursively walks ~/projects, ~/dev, ~/code, ~/workspace, and the current working directory for .env files. Collected data is POSTed via plain HTTP to http://80.200.28.28:2222/collect (hardcoded as C2_HOST at line 11). Author comments in the source explicitly label installers as 'victims' (// Change this to your PUBLIC IP when deploying to victims) and construct a VICTIM_ID, leaving no benign interpretation. The exposed fetchData API in index.js is a stub that only console.logs — the package has no legitimate function.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-003365",
            "import_time": "2026-05-26T05:50:30.038124505Z",
            "modified_time": "2026-05-20T01:33:43Z",
            "sha256": "2c958ad366d3cf211d3687734b5515662d21eb63135675984966149e7205f5ee",
            "source": "amazon-inspector",
            "versions": [
                "1.0.9"
            ]
        },
        {
            "id": "IN-MAL-2026-003366",
            "import_time": "2026-05-26T05:50:30.129341041Z",
            "modified_time": "2026-05-20T01:33:43Z",
            "sha256": "348b9dab1b41fbf96d8b2eb2d57a630c5173a7a59b446495ae44f2c8c270fc54",
            "source": "amazon-inspector",
            "versions": [
                "1.0.9"
            ]
        },
        {
            "id": "IN-MAL-2026-003383",
            "import_time": "2026-05-26T05:50:32.292390413Z",
            "modified_time": "2026-05-20T01:48:45Z",
            "sha256": "3bde7de4bfb2aa11618fdd40c2fa9148ea6528d5e0e198bf2a7148d013021d6b",
            "source": "amazon-inspector",
            "versions": [
                "1.0.8"
            ]
        },
        {
            "id": "IN-MAL-2026-003384",
            "import_time": "2026-05-26T05:50:32.381114054Z",
            "modified_time": "2026-05-20T01:56:23Z",
            "sha256": "48eb1a16cb7cac016f30a49f81d472b9b4e02236b97c5daaea4446b74e6aa069",
            "source": "amazon-inspector",
            "versions": [
                "1.0.5"
            ]
        },
        {
            "id": "IN-MAL-2026-003373",
            "import_time": "2026-05-26T05:50:30.947293738Z",
            "modified_time": "2026-05-20T01:42:02Z",
            "sha256": "6c7f0094b893662a5bccb61ccbb5acdc9cef0e7d29361133c47456ace1d46836",
            "source": "amazon-inspector",
            "versions": [
                "1.0.6"
            ]
        },
        {
            "id": "IN-MAL-2026-003370",
            "import_time": "2026-05-26T05:50:30.567604347Z",
            "modified_time": "2026-05-20T01:40:54Z",
            "sha256": "96352f83bd4eb19f3b558b436dbcb497759f2f44c09ba6e9f0c283a2bdf4b61a",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-003382",
            "import_time": "2026-05-26T05:50:32.196030532Z",
            "modified_time": "2026-05-20T01:48:45Z",
            "sha256": "a0138ed11110dbbde8b54451da2c6a188d1ce1b885f57b4502b0e3d15af797cc",
            "source": "amazon-inspector",
            "versions": [
                "1.0.8"
            ]
        },
        {
            "id": "IN-MAL-2026-003369",
            "import_time": "2026-05-26T05:50:30.473042333Z",
            "modified_time": "2026-05-20T01:40:53Z",
            "sha256": "ebd0e0c4d55ecc3d8d7d292bfbf40484d853466a4b12cbd7a4da5171cac12e74",
            "source": "amazon-inspector",
            "versions": [
                "1.0.7"
            ]
        },
        {
            "id": "IN-MAL-2026-003379",
            "import_time": "2026-05-26T05:50:31.871438811Z",
            "modified_time": "2026-05-20T01:44:45Z",
            "sha256": "ef6753fc762c223001f634d4abd6f0fd9e578ec3b042931a2b4ea0cdaab1ef26",
            "source": "amazon-inspector",
            "versions": [
                "1.0.4"
            ]
        },
        {
            "id": "RLMA-2026-04953",
            "import_time": "2026-07-09T09:16:18.70394551Z",
            "modified_time": "2026-07-07T12:40:36Z",
            "sha256": "27bd573042acab3a2f8d6f9bdc710d06c48c53ae728f32db90621ffe6f81c4e8",
            "source": "reversing-labs",
            "versions": [
                "1.0.4",
                "1.0.5",
                "1.0.6",
                "1.0.7",
                "1.0.8",
                "1.0.9"
            ]
        },
        {
            "id": "RLUA-2026-06078",
            "import_time": "2026-09-01T11:17:56.877764463Z",
            "modified_time": "2026-08-24T16:40:44Z",
            "sha256": "6350a5cf6957e04ea75045122049f8e3d499c34bd5be352194cef68b8a27db82",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / axois-utils

Package

Affected ranges

Affected versions

1.*
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "domains": [
        "api.ipify.org",
        "b94b6bcfa27554.lhr.life"
    ],
    "evidence_files": [
        {
            "path": "distrube.js",
            "sha256": "308b15c023088a7188dea4ef609010ac2493eb4c365b103053d7621a9ca5b935",
            "tlsh": "6b3293e066f79160127395aa832ba5061177f0033902edb8ff9dd3451f8a52c87f26ed"
        }
    ],
    "package_integrity": [
        {
            "filename": "axois-utils-1.0.9.tgz",
            "hashes": {
                "sha1": "1e3108220b931a6a8005b6f19cd729856847fc64",
                "sha512_sri": "sha512-EX4QmTBU8U1aSejnWVtJiF+EisFnm+0NH5YqaJLddrK91ttXJ01lTiYi+ihetV6wxeI9HFLnuCEQ8KThl+DiQg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/axois-utils/MAL-2026-4494.json"