MAL-2026-5672

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vqlxjmpr/MAL-2026-5672.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5672
Aliases
  • GHSA-4mx5-f4mw-64v7
Published
2026-06-11T14:09:37Z
Modified
2026-06-12T20:01:58.094772889Z
Summary
Malicious code in vqlxjmpr (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (aeb63fbed71a85092bf04cb120b4d1f19a3edaa74ac1c0cb47ce36f622d0062e)

Package is published as a generic 'Utility library' under an opaque name (vqlxjmpr) with no repository or homepage, but its sole exported function fetches a list of IDs from a hardcoded remote endpoint at https://isusbsjsu.vercel.app/api/newsletters and, for each ID returned, invokes bot.subscribeNewsletter / bot.newsletterFollow / bot.newsletter on the caller-supplied bot object (index.js line 6 defines the WEBURL constant; index.js lines 39-44 iterate the remote list and call botmethod). A consumer wiring this module into a WhatsApp/Baileys-style bot will silently force the bot's identity to follow whatever channels the package author chooses to push from the remote endpoint, with results persisted to cache/nlcache.json to avoid re-following. The followed-channel list is mutable and entirely author-controlled, so the package can change which newsletters every downstream bot follows at any time without a new release. This is silent-relay abuse: the package's advertised purpose hides the fact that normal use of its API hands the caller's bot capability to the author.

Source: ghsa-malware (1bdcc295891f10380c7f487d7ea61c1bd17d7230a8feed4f12d04b8aa7bddcaa)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "GHSA-4mx5-f4mw-64v7",
            "sha256": "1bdcc295891f10380c7f487d7ea61c1bd17d7230a8feed4f12d04b8aa7bddcaa",
            "modified_time": "2026-06-11T14:09:37Z",
            "ranges": [
                {
                    "type": "SEMVER",
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ]
                }
            ],
            "source": "ghsa-malware",
            "import_time": "2026-06-11T15:26:36.940319049Z"
        },
        {
            "id": "IN-MAL-2026-006124",
            "sha256": "aeb63fbed71a85092bf04cb120b4d1f19a3edaa74ac1c0cb47ce36f622d0062e",
            "modified_time": "2026-06-12T19:09:29Z",
            "versions": [
                "1.0.4"
            ],
            "source": "amazon-inspector",
            "import_time": "2026-06-12T19:44:10.768188159Z"
        },
        {
            "source": "amazon-inspector",
            "sha256": "c74ecc6c3a9e8075a6f7c5d2927311dfa5c61bc302de7f76f0fd1796852d8d73",
            "import_time": "2026-06-12T19:44:10.668234934Z",
            "modified_time": "2026-06-12T19:09:28Z",
            "id": "IN-MAL-2026-006123",
            "versions": [
                "1.0.3"
            ]
        },
        {
            "modified_time": "2026-06-12T19:09:26Z",
            "sha256": "ed2bc3aa005eac621d9ebd8830e2857d0c87e62e0b338e61e4b77d2fd83c064f",
            "versions": [
                "1.0.2"
            ],
            "import_time": "2026-06-12T19:44:10.556099352Z",
            "source": "amazon-inspector",
            "id": "IN-MAL-2026-006122"
        },
        {
            "source": "amazon-inspector",
            "sha256": "54d3db396a27ff5caf54d7caa79ea1bbed4654138eec75e62df3942a0311571e",
            "import_time": "2026-06-12T19:44:10.448746595Z",
            "modified_time": "2026-06-12T19:09:24Z",
            "id": "IN-MAL-2026-006121",
            "versions": [
                "1.0.1"
            ]
        },
        {
            "import_time": "2026-06-12T19:44:10.34036081Z",
            "sha256": "67cc634f86d669ecd573720384a27dd6bd212688570e0642fc1742d2a9e387a7",
            "modified_time": "2026-06-12T19:09:23Z",
            "versions": [
                "1.0.0"
            ],
            "id": "IN-MAL-2026-006120",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / vqlxjmpr

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "evidence_files": [
        {
            "tlsh": "96310f6b41fb263100f372ee1a8f200fe219e4133286dfd1fe6d81252f83558869299c",
            "sha256": "c25694dfd03be73eb59109c98a484bd3a8abf71ba858e05767b286f271da302a",
            "path": "index.js"
        },
        {
            "tlsh": "f6e0c2308e65687326d85a622d2d8246b1655d070048bd0c73d3223d57df76394b865c",
            "sha256": "6e429c129e36b36c828d55635b79d613823ffc997fb55a7a8eb9cf6ca324a97e",
            "path": "package.json"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/vqlxjmpr/MAL-2026-5672.json"