MAL-2026-4593

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/klaudius/MAL-2026-4593.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4593
Withdrawn
2026-05-26T18:41:27Z
Published
2026-05-20T10:02:46Z
Modified
2026-05-27T00:32:11.540614198Z
Summary
Malicious code in klaudius (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f0b40ecfc7aa434ac63d620d4aaab0434dd57b0fac274bb9f5d1514e263be4a3)

The package's CLI bundle (dist/bin.js) and an associated chunk (dist/chunk-SZ4KCTSL.js) contain hardcoded fetch() POST calls to https://api.telegram.org, the canonical Telegram Bot API endpoint used as a hardcoded C2/exfiltration channel. A Telegram bot endpoint embedded in a CLI tool's compiled bundle, invoked via fetch with POST, is the standard fingerprint of an exfiltration beacon: api.telegram.org acts as a free, TLS-protected, attacker-controlled relay where a hardcoded bot token receives whatever the package decides to send (env vars, file contents, command output, host identifiers). When the CLI is run, anything routed through these calls leaves the installer's machine to a Telegram chat the package author controls. The destination is not user-configurable in the typical Telegram-bot integration shape — the bot token and chat id are baked into the bundle.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004471",
            "import_time": "2026-05-26T05:52:39.949875333Z",
            "sha256": "4602750d9182431bfaad2c7ea7cfec4f59e4dd7dbc5cf369693bd79a6599163a",
            "versions": [
                "0.12.3"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-05-24T08:18:35Z"
        },
        {
            "id": "IN-MAL-2026-003515",
            "import_time": "2026-05-26T05:50:46.472606799Z",
            "sha256": "8d7da4a8274b183b4f47bc8fd2f64aeef673d34411b6009c7ac8899605625bbc",
            "modified_time": "2026-05-20T10:02:46Z",
            "source": "amazon-inspector",
            "versions": [
                "0.9.0"
            ]
        },
        {
            "id": "IN-MAL-2026-004302",
            "import_time": "2026-05-26T05:52:20.067543734Z",
            "sha256": "b00b058dddd8480cee3ae55bed752889ba97591a4658c2d218fab11d984dbceb",
            "modified_time": "2026-05-23T08:51:21Z",
            "source": "amazon-inspector",
            "versions": [
                "0.12.1"
            ]
        },
        {
            "import_time": "2026-05-26T05:52:20.901218055Z",
            "id": "IN-MAL-2026-004308",
            "sha256": "e60fbd49d8e4939542d56d50b9f518d230b255c1f8f1b14abde52e8eeedec339",
            "modified_time": "2026-05-23T09:56:34Z",
            "source": "amazon-inspector",
            "versions": [
                "0.12.2"
            ]
        },
        {
            "id": "IN-MAL-2026-003818",
            "import_time": "2026-05-26T05:51:22.722455449Z",
            "sha256": "f0b40ecfc7aa434ac63d620d4aaab0434dd57b0fac274bb9f5d1514e263be4a3",
            "versions": [
                "0.11.0"
            ],
            "source": "amazon-inspector",
            "modified_time": "2026-05-21T13:18:47Z"
        },
        {
            "import_time": "2026-05-26T05:52:06.991145805Z",
            "id": "IN-MAL-2026-004192",
            "sha256": "574558e1dcab4465b74d0553fa7e1a18a1df9495e3002f93e0ca87e856f74d03",
            "modified_time": "2026-05-22T10:51:40Z",
            "source": "amazon-inspector",
            "versions": [
                "0.12.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / klaudius

Package

Affected ranges

Affected versions

0.*
0.9.0
0.11.0
0.12.0
0.12.1
0.12.2
0.12.3

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/bin.js",
            "tlsh": "e4632b2293ee267f67b91161f44a1027e2b09c1447059075b3bdc16fa771828b3fbfa5",
            "sha256": "95e148b0d155004253cdb3f4375dff4b69ffa07d9c983f4877f784d6ba11e73c"
        },
        {
            "path": "dist/chunk-SZ4KCTSL.js",
            "tlsh": "d071c6df9b6bee3b03d610933148706f5672c144490bd231728895772b2a4a2c9b3f49",
            "sha256": "890622ca859a2fc02f9ce87e0da543dda6fbea303e1e060dcbe6816eccc80c97"
        }
    ],
    "package_integrity": [
        {
            "filename": "klaudius-0.12.3.tgz",
            "hashes": {
                "sha1": "73ddf7fa64feb5f04701cfc00f9a65abbf6ca9a8",
                "sha512_sri": "sha512-PB5rgmUNRNQAx8TL+QquAaHjGHmn0K8t8wWCvg5YsI9VFDC9unWDfBW0fHFP7nfq6kRHlQ1cTLbJlssppN7/ng=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/klaudius/MAL-2026-4593.json"