MAL-2026-4497

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bingocode/MAL-2026-4497.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4497
Published
2026-05-22T06:25:45Z
Modified
2026-06-12T20:01:47Z
Summary
Malicious code in bingocode (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (78f3d873e7c4d16629263bb242a2636f18747d5dd096b614fb3cf43a56d2dc8e)

The package declares bin.claude pointing at bin/claude-win.cjs (and bin/claude on Linux/macOS). After npm i -g bingocode, the claude command on PATH is this package, not Anthropic's official @anthropic-ai/claude-code. On first invocation, each bin script runs deployBingoDefaults() which copies config/bingo-defaults/settings.json into ~/.claude/bingo/settings.json; the shipped settings pin ANTHROPIC_BASE_URL to http://127.0.0.1:3456 and the package's .env.example documents routing prompts through MiniMax / OpenRouter / DeepSeek backends. The net effect: a user who types claude expecting Anthropic's CLI gets their prompts (and any associated auth) silently brokered through a local proxy under this package's control, then forwarded to author-chosen LLM providers. The npm postinstall hook (scripts/install-skills.cjs) additionally copies bundled skill directories into ~/.claude/skills/ (Anthropic Claude's user-config namespace), giving this package script-level influence over the sibling tool's behavior. On Linux/macOS, bin/claude also runs npm install -g bun at first invocation if bun is missing — privileged global install without explicit consent, though the package fetched is pinned-by-name from the public npm registry. The combination of bin-name hijack + seeded settings redirecting the API base URL is the silent-relay shape: caller-supplied prompts route to a destination the caller did not choose. The YARA js_network_command_exfiltration hits on src/bridge/bridgeMain.ts, src/services/mcp/*, src/utils/hooks/execHttpHook.ts, etc. are pattern-matches on code vendored from Anthropic's open-source Claude Code (bridge poll loops, MCP client, SSRF-guarded http-hook with URL allowlist) and do not represent installer-harm behavior on their own.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004149",
            "import_time": "2026-05-26T05:52:01.866295474Z",
            "modified_time": "2026-05-22T06:25:45Z",
            "sha256": "7bb3ff21cce9379a60d3ebe3408d8c179e39cfd940eed6deb4afb2f28d852254",
            "source": "amazon-inspector",
            "versions": [
                "1.1.123"
            ]
        },
        {
            "id": "IN-MAL-2026-005809",
            "import_time": "2026-06-12T19:43:35.686434656Z",
            "modified_time": "2026-06-12T19:02:23Z",
            "sha256": "78f3d873e7c4d16629263bb242a2636f18747d5dd096b614fb3cf43a56d2dc8e",
            "source": "amazon-inspector",
            "versions": [
                "1.1.163"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / bingocode

Package

Affected ranges

Affected versions

1.*
1.1.123
1.1.163

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "a3ff12efe74a2abf8b05b6321bb04894b3a16f9c7ee690a3e3b2d49d0fd9bbbb",
            "tlsh": "0671cd23cd55cea345faaad9bc3a0a66f124571f2100c4cf33b547dd4fb5a2a2089b61"
        },
        {
            "path": "bin/bingo-win.cjs",
            "sha256": "4538c7d701c8690c25075a6a36f693ceb9710c7553c196bb08c04fd3a71633eb",
            "tlsh": "958171d9545767785ef15f689b07040bfd6e68b33a02e254f9cc02ca6f705584242efe"
        }
    ],
    "package_integrity": [
        {
            "filename": "bingocode-1.1.123.tgz",
            "hashes": {
                "sha1": "54f12fbe81bd537b8eb32ca32644aeb022ed9bcc",
                "sha512_sri": "sha512-mk5PnU0PZtFRn0Hh9apQB8ePS/pbdnndRBL5Sly5LwciRxNDHswHFP3OhQvYJERloyOcxwOGHp7hyMuLpZgYTw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bingocode/MAL-2026-4497.json"