-= Per source details. Do not edit below this line.=-
package.json declares "postinstall": "node install.js", which runs at install time. install.js requires both child_process and https, branches on process.platform to enumerate host details, and issues an outbound https.get(...) carrying the collected data. This is the canonical install-time system-information exfiltration shape: child_process to spawn host-info commands, platform-gated logic to pick the right binary per OS, and HTTPS egress to ship the result. There is no legitimate reason for a CLI's postinstall to gather host metadata and POST/GET it off-host. Installing this package on any machine (developer laptop, CI runner, build server) discloses host details to a remote endpoint and provides an install-time code-execution surface.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004147",
"import_time": "2026-05-26T05:52:01.666435355Z",
"modified_time": "2026-05-22T06:16:26Z",
"sha256": "80b70f02e409ec9eb28e4ddcdf37d477f4ffe774ff0a4026f0e242dcc0a1ef48",
"source": "amazon-inspector",
"versions": [
"0.2.0"
]
},
{
"id": "IN-MAL-2026-004146",
"import_time": "2026-05-26T05:52:01.559120786Z",
"modified_time": "2026-05-22T06:16:26Z",
"sha256": "8a7070dd3d284cb91d046f6be633445a29af8e30a4fc0d3c77dce18bf847c0b0",
"source": "amazon-inspector",
"versions": [
"0.2.0"
]
},
{
"id": "IN-MAL-2026-003529",
"import_time": "2026-05-26T05:50:48.039101961Z",
"modified_time": "2026-05-20T12:36:32Z",
"sha256": "b4eea8e53244b7114760ece8c8842f1936baca2e93ba8f49c76f7d02e7f0ffb6",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
},
{
"id": "IN-MAL-2026-003528",
"import_time": "2026-05-26T05:50:47.903193915Z",
"modified_time": "2026-05-20T12:36:31Z",
"sha256": "e98813f52fa8e9fc3c04bffd023445dbfed4a9b405d1e3f85511673f5e86dce7",
"source": "amazon-inspector",
"versions": [
"0.1.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"github.com"
],
"evidence_files": [
{
"path": "install.js",
"sha256": "c86aeb8a58c9f21a7e7a27d663f9edb009d7bffaa482c8034d0e91bc23adb8f5",
"tlsh": "8551950d97e252305eb052e7b98b1c17e49b02237706cd88f2ac46183ff6d6495a63eb"
},
{
"path": "package.json",
"sha256": "3050a2eaa30e1acece5878910cbd1e84b6ab2a389afee13a3ea36e411985941e",
"tlsh": "5e0199288e3109133bd895a81d99240a7523190b0cc47c263baf003d17ce23a207e2fe"
}
],
"package_integrity": [
{
"filename": "encrata-cli-0.2.0.tgz",
"hashes": {
"sha1": "90d211a7c3dc95b23f4a17bd7753e6331bf4cf90",
"sha512_sri": "sha512-gQwz1rVjTnIh7tySZb1kMHDuCyxsVZyH2I7DSMXDw596Ko7YNtm0r1e8U7RiSXiI7c6geggXwgorVzDhzxDYFw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/encrata-cli/MAL-2026-4551.json"