MAL-2026-4527

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/clawpro-diagnostics-metrics-cls/MAL-2026-4527.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4527
Withdrawn
2026-05-26T18:37:19Z
Published
2026-05-25T11:35:40Z
Modified
2026-05-27T00:32:12Z
Summary
Malicious code in clawpro-diagnostics-metrics-cls (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (7d176cad00849132cb8df7ca53ac064e1980cea09bfe9b25836a78b4719b08ea)

The package's dist/index.js contains hardcoded HTTP POST calls targeting http://metadata.tencentyun.com along with reads of process.platform and related host identifiers. The endpoint is a cloud-metadata-style hostname being contacted over plain HTTP from package code, not a documented SDK. The package name ("diagnostics-metrics") combined with hardcoded outbound POSTs to a fixed external endpoint at module load matches the silent-beacon / data-exfiltration shape: any installer that requires this package will have host attributes transmitted to the hardcoded destination without consent or configuration.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004630",
            "import_time": "2026-05-26T05:52:58.976849552Z",
            "modified_time": "2026-05-25T11:35:40Z",
            "sha256": "7d176cad00849132cb8df7ca53ac064e1980cea09bfe9b25836a78b4719b08ea",
            "source": "amazon-inspector",
            "versions": [
                "3.0.4"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / clawpro-diagnostics-metrics-cls

Package

Name
clawpro-diagnostics-metrics-cls
View open source insights on deps.dev
Purl
pkg:npm/clawpro-diagnostics-metrics-cls

Affected ranges

Affected versions

3.*
3.0.4

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/index.js",
            "sha256": "3acec37ae37504b3b6cbd7af9eb99a596e52c8ea1f9fb84545f3a92877082135",
            "tlsh": "7ff33a5db7b170374bda918ae4211503b2aa6d004009857df3fca9fe769944ea2f3f78"
        }
    ],
    "package_integrity": [
        {
            "filename": "clawpro-diagnostics-metrics-cls-3.0.4.tgz",
            "hashes": {
                "sha1": "552c049c1241acaf1be9fe15e7073c1ceee69768",
                "sha512_sri": "sha512-6OYThPhUY1Q68k21EoGcpunhAVDdJjTGg7wSWk8SNbz5za4zuBtI6UIKGzRqAjUxbH90lenwyvswULHFNTfSaw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/clawpro-diagnostics-metrics-cls/MAL-2026-4527.json"