-= Per source details. Do not edit below this line.=-
The package's dist/index.js contains hardcoded HTTP POST calls targeting http://metadata.tencentyun.com along with reads of process.platform and related host identifiers. The endpoint is a cloud-metadata-style hostname being contacted over plain HTTP from package code, not a documented SDK. The package name ("diagnostics-metrics") combined with hardcoded outbound POSTs to a fixed external endpoint at module load matches the silent-beacon / data-exfiltration shape: any installer that requires this package will have host attributes transmitted to the hardcoded destination without consent or configuration.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004630",
"import_time": "2026-05-26T05:52:58.976849552Z",
"modified_time": "2026-05-25T11:35:40Z",
"sha256": "7d176cad00849132cb8df7ca53ac064e1980cea09bfe9b25836a78b4719b08ea",
"source": "amazon-inspector",
"versions": [
"3.0.4"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "dist/index.js",
"sha256": "3acec37ae37504b3b6cbd7af9eb99a596e52c8ea1f9fb84545f3a92877082135",
"tlsh": "7ff33a5db7b170374bda918ae4211503b2aa6d004009857df3fca9fe769944ea2f3f78"
}
],
"package_integrity": [
{
"filename": "clawpro-diagnostics-metrics-cls-3.0.4.tgz",
"hashes": {
"sha1": "552c049c1241acaf1be9fe15e7073c1ceee69768",
"sha512_sri": "sha512-6OYThPhUY1Q68k21EoGcpunhAVDdJjTGg7wSWk8SNbz5za4zuBtI6UIKGzRqAjUxbH90lenwyvswULHFNTfSaw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/clawpro-diagnostics-metrics-cls/MAL-2026-4527.json"