MAL-2026-4788

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@godscene/web/MAL-2026-4788.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4788
Withdrawn
2026-05-26T21:28:12Z
Published
2026-05-26T08:06:37Z
Modified
2026-05-27T00:31:55Z
Summary
Malicious code in @godscene/web (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (e1bd83a63f0426cc7c4e1a68886c36ff47de093d9b7edc6b410d16c928be50c1)

Package @godscene/web@1.7.22 is a re-bundled copy of the legitimate @midscene/web at the same version, preserving the original description, README, repository URL (web-infra-dev/midscene), homepage, class names, and exports. Only the scope was changed from @midscene to @godscene. The package.json rewrites the original dependencies @midscene/core, @midscene/shared, and @midscene/playground to @godscene/core@1.7.22, @godscene/shared@1.7.22, and @godscene/playground@1.7.22 — packages published under the attacker-controlled @godscene scope and outside this tarball. Installing or requiring this package transitively pulls and loads those attacker-controlled siblings, whose contents are not vetted by this wrapper. The wrapper itself contains no lifecycle hooks or overtly hostile code; the supply-chain attack edge is the dependency redirection into a hostile namespace, achieved by impersonating a legitimate package's identity.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004866",
            "import_time": "2026-05-26T09:17:31.820785783Z",
            "modified_time": "2026-05-26T08:06:37Z",
            "sha256": "e1bd83a63f0426cc7c4e1a68886c36ff47de093d9b7edc6b410d16c928be50c1",
            "source": "amazon-inspector",
            "versions": [
                "1.7.22"
            ]
        },
        {
            "id": "IN-MAL-2026-004867",
            "import_time": "2026-05-26T09:17:31.929537505Z",
            "modified_time": "2026-05-26T08:06:38Z",
            "sha256": "fe8a40a240d852a17faba624022dc9e2675f6041d3ac559b454c23fdd1f874ab",
            "source": "amazon-inspector",
            "versions": [
                "1.7.22"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @godscene/web

Package

Name
@godscene/web
View open source insights on deps.dev
Purl
pkg:npm/%40godscene%2Fweb

Affected ranges

Affected versions

1.*
1.7.22

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "domains": [
        "34.5.16.104.in-addr.arpa"
    ],
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "4cdd211f921ed03392de1ccbe5c5a66e9f0910915f21738eeb636e63d288f544",
            "tlsh": "24c15419c4e91d6332d16ab2e66a2235b27281474b147f1473c9027c4f8c7ef12bf6ae"
        }
    ],
    "package_integrity": [
        {
            "filename": "web-1.7.22.tgz",
            "hashes": {
                "sha1": "d8379086809247b010235fd00339957c9a2181e8",
                "sha512_sri": "sha512-g6PJmsAFaRRSxUY2+lkM4SqyiMbJ7UXCEpO7AZo92R234XXJtimjLbSSz7uadH5cvgmcCqaeAj+0b8d9rcibrg=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/withdrawn/npm/@godscene/web/MAL-2026-4788.json"