-= Per source details. Do not edit below this line.=-
Package is published as @solana-labs/ancor — a name one character off from anchor, the well-known Solana smart-contract framework (published as @coral-xyz/anchor, formerly @project-serum/anchor). The @solana-labs scope and the near-miss spelling ancor together create high confusion potential for developers searching for the Anchor framework. The shipped bundles lib/index.cjs.js and lib/index.esm.js are large minified rollups (~11k+ lines) that include require('child_process'), fetch(...) POST calls, and references to curl / ping. Pattern matches on keyword co-occurrence in a minified bundle do not by themselves prove malicious intent — Anchor and similar frameworks legitimately bundle childprocess and HTTP for build/CLI tooling — but the combination of a typosquat-shaped name, a vendor-impersonating scope, and a large opaque bundle warrants human review before this version is allowed into installer environments. A reviewer should verify scope ownership (is @solana-labs actually controlled by Solana Labs, or a squatted scope?), de-minify the flagged regions around lines 5016/5046 and 11336/11441 to confirm whether the POST/fetch destinations and childprocess spawns are part of a documented build/CLI flow or an exfiltration path, and compare bundle behavior against legitimate @coral-xyz/anchor.
{
"malicious-packages-origins": [
{
"import_time": "2026-06-15T17:22:53.536535124Z",
"sha256": "06e80dfe88b6d601c9312c9fc13275b703e5d05311232a3f1fa01b1c0a1f041b",
"modified_time": "2026-06-15T17:17:28Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006600",
"versions": [
"1.0.1"
]
},
{
"import_time": "2026-06-15T17:22:53.441442777Z",
"source": "amazon-inspector",
"modified_time": "2026-06-15T17:17:27Z",
"sha256": "4341f9b2c0176d9259176539e69a12bec21bd872733a220066f2af7e8c852012",
"id": "IN-MAL-2026-006599",
"versions": [
"1.0.1"
]
},
{
"import_time": "2026-06-15T17:22:53.323149768Z",
"source": "amazon-inspector",
"modified_time": "2026-06-15T17:17:25Z",
"sha256": "a2dc1225b1e56ff04b029102d142b130bf7d9f65e2458034cd7ef630dcdaf5eb",
"id": "IN-MAL-2026-006597",
"versions": [
"1.0.8"
]
},
{
"import_time": "2026-06-15T17:22:52.810954547Z",
"source": "amazon-inspector",
"modified_time": "2026-06-15T17:17:22Z",
"sha256": "e5786abeec93a264217ec9d4ca101ba0f491867bacf387dfd15e891fde36b634",
"id": "IN-MAL-2026-006592",
"versions": [
"1.0.9"
]
},
{
"import_time": "2026-06-15T17:22:53.386804733Z",
"sha256": "0e572d1a61685cd04ccafca460d47a230f0306cca7692e3c1008f2b296592b22",
"modified_time": "2026-06-15T17:17:25Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006598",
"versions": [
"1.0.8"
]
},
{
"import_time": "2026-06-15T17:22:52.70320754Z",
"sha256": "3b513d317445b8431eda1751d82e7f50d2d7ef311a9891a7aa9a2fab706236c5",
"modified_time": "2026-06-15T17:17:18Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006590",
"versions": [
"1.0.0"
]
},
{
"import_time": "2026-06-15T17:22:52.659805192Z",
"sha256": "3c3f14460d22b93718d3fdf4337cc9b5f3a2526e4cb265a906a9c24d87671f98",
"modified_time": "2026-06-15T17:17:17Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006589",
"versions": [
"1.0.0"
]
},
{
"import_time": "2026-06-15T17:22:52.929386825Z",
"sha256": "42c4ffd55383e8703ce8de56e582e1e0eaa2b57d522edb4b4356febd4134e6a5",
"modified_time": "2026-06-15T17:17:22Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006593",
"versions": [
"1.0.11"
]
},
{
"import_time": "2026-06-15T17:22:52.749849529Z",
"sha256": "4d59b87155558b811b79a7d671f6dcd66bee47adff3a7022ab22d73f18d86369",
"modified_time": "2026-06-15T17:17:21Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006591",
"versions": [
"1.0.11"
]
},
{
"import_time": "2026-06-15T17:22:53.05279153Z",
"sha256": "5feff6d83078f902bd5e7eaa2dd81f78c95289d86ccfcde5f30325c7609278a7",
"modified_time": "2026-06-15T17:17:23Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006594",
"versions": [
"1.0.9"
]
},
{
"import_time": "2026-06-15T17:22:53.174797033Z",
"source": "amazon-inspector",
"modified_time": "2026-06-15T17:17:23Z",
"sha256": "8e001b6b18e1b0a1841b10d5e41b1403383d65f61e56f5363efcfc4102162892",
"id": "IN-MAL-2026-006595",
"versions": [
"1.0.7"
]
},
{
"import_time": "2026-06-15T17:22:53.241896585Z",
"sha256": "c2e55c8cd359b7c45614d01f3d8f02bd9f27a9322c52decf65b1524500a0a396",
"modified_time": "2026-06-15T17:17:24Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-006596",
"versions": [
"1.0.7"
]
},
{
"import_time": "2026-07-20T13:14:42.204993192Z",
"sha256": "70c0dda7b6c720ce80dd63fb61128fb18e31dbf5d8c6842fa193ac2390e90b0c",
"modified_time": "2026-07-20T10:28:14Z",
"source": "reversing-labs",
"id": "RLMA-2026-05466",
"versions": [
"1.0.0",
"1.0.1",
"1.0.3",
"1.0.4",
"1.0.5",
"1.0.6",
"1.0.7",
"1.0.8",
"1.0.9",
"1.0.11",
"1.98.103",
"1.98.105",
"1.98.107",
"1.98.108",
"1.98.109",
"1.98.110",
"1.98.111",
"1.98.112"
]
},
{
"import_time": "2026-08-05T06:00:27.088725318Z",
"sha256": "314cf23ddf6ccc41d2ef7db753d938cb43fa48d9831898121a2242de1bc02705",
"modified_time": "2026-08-05T05:16:51Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-012981",
"versions": [
"1.98.108"
]
},
{
"import_time": "2026-08-05T06:00:26.152164255Z",
"sha256": "3265b293c8d6ebf4e866644687ab8bb9f03345c704acf7c885574886ad396b5b",
"modified_time": "2026-08-05T05:15:30Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-012972",
"versions": [
"1.98.110"
]
},
{
"import_time": "2026-08-05T06:00:26.770716766Z",
"sha256": "3d9b7772c3a290a2df1dab3f463f81b7858eb46014bdf5894d87085300b27eaa",
"modified_time": "2026-08-05T05:16:21Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-012978",
"versions": [
"1.98.109"
]
},
{
"import_time": "2026-08-05T06:00:28.19115161Z",
"sha256": "66b793954230a8961373ff13632dea3f9142617883313255138a279d18f135e5",
"modified_time": "2026-08-05T05:18:15Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-012991",
"versions": [
"1.0.3"
]
},
{
"import_time": "2026-08-05T06:00:28.464479959Z",
"sha256": "c4eb809cfad458ca8ae6023a958903efc0280e4a262fe0494e079edc55ed1baa",
"modified_time": "2026-08-05T05:18:36Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-012993",
"versions": [
"1.0.4"
]
},
{
"import_time": "2026-08-05T06:00:25.953644442Z",
"source": "amazon-inspector",
"modified_time": "2026-08-05T05:15:15Z",
"sha256": "2a6b346d7986ec82a886c6b717340b2431585bcb3e7d404ff79ffba00c6e664c",
"id": "IN-MAL-2026-012970",
"versions": [
"1.98.111"
]
},
{
"import_time": "2026-08-05T06:00:27.969796188Z",
"source": "amazon-inspector",
"modified_time": "2026-08-05T05:17:57Z",
"sha256": "2aa229b377555123d264a04dcedb4380d56b34f88359704038d09d8cfabda744",
"id": "IN-MAL-2026-012989",
"versions": [
"1.0.5"
]
},
{
"import_time": "2026-08-05T06:00:27.74679233Z",
"sha256": "49b37772a8993dfe253fc690b3d1805738bbfcc124faedd415e4b48c6518fee8",
"modified_time": "2026-08-05T05:17:40Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-012987",
"versions": [
"1.98.105"
]
},
{
"import_time": "2026-08-05T06:00:34.030479588Z",
"sha256": "adb9cf699c9d3cdc61f5ce194874e12de5a8db37140b162a6c76bb83ee483db1",
"modified_time": "2026-08-05T05:25:11Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-013039",
"versions": [
"1.98.103"
]
},
{
"import_time": "2026-08-05T06:00:27.192126204Z",
"source": "amazon-inspector",
"modified_time": "2026-08-05T05:16:58Z",
"sha256": "ddf942b3608ccb23c6d9fad14219183b15ded3594816b61046127c2c139893e7",
"id": "IN-MAL-2026-012982",
"versions": [
"1.98.107"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@solana-labs/ancor/MAL-2026-5786.json"
{
"evidence_files": [
{
"sha256": "26862c85e8b88b8dcf7606678c286130b852dda467257d6e781c1c02293fc913",
"path": "install.js",
"tlsh": "5a82e8a506fa5a2456a7f6ac3f0f5019251be10b3508ed55b94c8f946f8932883f2fec"
},
{
"sha256": "586b641329f23e586cefeef5391e2fe64038b671abc3ea7feb1e27a48a32fd7e",
"tlsh": "9ad05b641b629d332dc45e9b0d33424d26751d174150744d1b9f3108d19d7b7e8ba62e",
"path": "package.json"
}
],
"ips": [
"34.160.111.145",
"149.154.166.110",
"104.16.10.34",
"10.1.0.2"
],
"domains": [
"ifconfig.me",
"api.telegram.org"
],
"package_integrity": [
{
"filename": "ancor-1.0.1.tgz",
"hashes": {
"sha1": "f3a17d5b7ce4972c58a87c9ddff158fe5b4135f4",
"sha512_sri": "sha512-f5xT6CykjGFIv9VehK/BeEtlU5pl5SQg52hAq+cBj2U6MHhuVQfVUs1tXD1V0BKsTg6EOVANcVx3ED0AlVXbWg=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]