MAL-2026-6210

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@apexcraft/nano-key/MAL-2026-6210.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6210
Aliases
  • GHSA-8x7w-vjr2-7q4m
Published
2026-06-19T15:12:42Z
Modified
2026-07-07T14:01:46Z
Summary
Malicious code in @apexcraft/nano-key (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c46938b3634fb4de89ddf44b765e1c766c871a40fb31c54609c1b3526074e65c)

@apexcraft/nano-key advertises itself as a 12-byte sortable ID generator (README and repository metadata are copied from yiwen-ai/xid-ts, an unrelated upstream project), but ships a 250KB obfuscator.io-style payload at dist/cjs/seed.cjs. package.json declares "postinstall": "node./dist/cjs/seed.cjs", so the payload runs automatically on npm install. The same runPrepare() entry point is also invoked at module load: index.js line 25 calls _seed.runPrepare() inside newState(), which line 35 invokes as defaultState = newState() at top level — so any consumer that requires the package re-triggers the dropper. seed.cjs uses an RC4+base64 rotating string array decoder (_0x554f / _0x1420), control-flow flattening, a self-defending IIFE, and a debugger-protection loop to hide an AES-256-GCM-decrypted URL list. At runtime it https.requests those URLs, stages the response under ~/.cache (or %LOCALAPPDATA% / ~/Library/Caches), sha256-stamps the file, and executes it with child_process.spawn(process.execPath, [file]), with an alternate bun runtime branch. There is no signature or hash pinning of the fetched bytes, the destination is decrypted at runtime (mutable C2), and the package's stated purpose (ID generation) provides no legitimate reason to fetch and execute remote code. Installing or requiring this package hands arbitrary remote code execution to whoever controls the encrypted endpoint.

Source: ghsa-malware (a93a588a8c86cfaf399f05f0c68352ac421adb4cd95f3d9c4ec6d340595c6c5a)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-007076",
            "import_time": "2026-06-19T15:41:55.51799058Z",
            "modified_time": "2026-06-19T15:12:42Z",
            "sha256": "a07948bbe7c664c2248fc90112dccc0258f9857706b50eed5f68e7ddd7dc6f62",
            "source": "amazon-inspector",
            "versions": [
                "1.3.8"
            ]
        },
        {
            "id": "IN-MAL-2026-007077",
            "import_time": "2026-06-19T15:41:55.586775548Z",
            "modified_time": "2026-06-19T15:12:44Z",
            "sha256": "c46938b3634fb4de89ddf44b765e1c766c871a40fb31c54609c1b3526074e65c",
            "source": "amazon-inspector",
            "versions": [
                "1.3.4"
            ]
        },
        {
            "id": "IN-MAL-2026-007281",
            "import_time": "2026-06-23T16:54:14.425995217Z",
            "modified_time": "2026-06-23T16:22:26Z",
            "sha256": "6e1f3a106793eefdb9448fdb9040376bc761c4cc09cc217a31ec74e11f8200e9",
            "source": "amazon-inspector",
            "versions": [
                "1.3.6"
            ]
        },
        {
            "id": "IN-MAL-2026-007329",
            "import_time": "2026-06-23T16:54:18.259907527Z",
            "modified_time": "2026-06-23T16:23:11Z",
            "sha256": "885a9cc08aeccde88eae2ef2b4a156d09beb7e5c21809ea102daedd1c885e162",
            "source": "amazon-inspector",
            "versions": [
                "1.2.5"
            ]
        },
        {
            "id": "IN-MAL-2026-007284",
            "import_time": "2026-06-23T16:54:14.686177786Z",
            "modified_time": "2026-06-23T16:22:29Z",
            "sha256": "a657ee39b6e6cd40da12f5cc8d9a04bd99d1b819e4d0178bcacc2c26b76f4262",
            "source": "amazon-inspector",
            "versions": [
                "1.3.2"
            ]
        },
        {
            "id": "IN-MAL-2026-007287",
            "import_time": "2026-06-23T16:54:14.917412094Z",
            "modified_time": "2026-06-23T16:22:32Z",
            "sha256": "ccaae5b4feb4a9161ba31930be6a9eab3a211acf9d5f4e22792e3faec5656191",
            "source": "amazon-inspector",
            "versions": [
                "1.3.5"
            ]
        },
        {
            "id": "IN-MAL-2026-007331",
            "import_time": "2026-06-23T16:54:18.393068018Z",
            "modified_time": "2026-06-23T16:23:13Z",
            "sha256": "d5623be1d4027affcd306453739c43895b277061ea3b983f59ae1e3780cd3bed",
            "source": "amazon-inspector",
            "versions": [
                "1.3.7"
            ]
        },
        {
            "id": "IN-MAL-2026-007326",
            "import_time": "2026-06-23T16:54:17.99339716Z",
            "modified_time": "2026-06-23T16:23:08Z",
            "sha256": "0a36493a82b254d89df5a033592050540837496ed40f64d3d9be8197dd30b2da",
            "source": "amazon-inspector",
            "versions": [
                "1.2.4"
            ]
        },
        {
            "id": "IN-MAL-2026-007327",
            "import_time": "2026-06-23T16:54:18.131346286Z",
            "modified_time": "2026-06-23T16:23:09Z",
            "sha256": "107a24e44a139d8b90655b72440349a9dfcc8cacbf18a7cecdb782b93af1fd66",
            "source": "amazon-inspector",
            "versions": [
                "1.3.3"
            ]
        },
        {
            "id": "GHSA-8x7w-vjr2-7q4m",
            "import_time": "2026-07-07T13:57:11.606420529Z",
            "modified_time": "2026-07-07T13:35:24Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "SEMVER"
                }
            ],
            "sha256": "a93a588a8c86cfaf399f05f0c68352ac421adb4cd95f3d9c4ec6d340595c6c5a",
            "source": "ghsa-malware"
        }
    ]
}
References
Credits

Affected packages

npm / @apexcraft/nano-key

Package

Name
@apexcraft/nano-key
View open source insights on deps.dev
Purl
pkg:npm/%40apexcraft%2Fnano-key

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.2.4
1.2.5
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "dist/cjs/seed.cjs",
            "sha256": "618dfffb6829356c131fded9f4c6528b73b4f9d7ff1fc1d3b457599a12584e29",
            "tlsh": "d1449730b3c07c9425479f7b332ef5e5f92e5fa934a8088bd065bc64a6ea915dad0730"
        },
        {
            "path": "package.json",
            "sha256": "4f42c7bd6028949d5899aa16a5a028ae8ab93a03b9ee509445fcadb521a077f1",
            "tlsh": "e0216b69c4b45d631be465e0ac6a1806a3710d078e64be0537df407caf8e1ab52bf3ac"
        }
    ],
    "package_integrity": [
        {
            "filename": "nano-key-1.3.8.tgz",
            "hashes": {
                "sha1": "8edf857e84e1a2e28225c7e4a3bf99bea3a189a8",
                "sha512_sri": "sha512-tr//m4xj70vcDmTb0nme74hwqRLk6PPewyeMHhfIGiR69ITBwXN8Fj4kZ4KPVT5OMLv/GIj607BS47YzZUdGvQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@apexcraft/nano-key/MAL-2026-6210.json"